> For the complete documentation index, see [llms.txt](https://ztrust.gitbook.io/ztrust-documentation/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ztrust.gitbook.io/ztrust-documentation/user-manual-ztrust-v4.1/4.-admin-manual/4.13-set-up-multi-factor-authentication/4.13.10-how-to-set-up-2fa-authentication.md).

# 4.13.10 How to set-up 2FA Authentication

*Two-Factor Authentication (2FA), in ZTrust, is a security process that requires users to provide two different forms of identification to access an account or system, such as a password and a push notification from the ZTrust Authenticator mobile application.*

## Use Case

* Admin able to configure the 2FA authentication flow.
* Users should be able to login by using the configured 2FA flow.
* ZTrust supports the following as first factor authentication:
  * Username Password
  * Push Notification
  * QR Code
  * Email OTP
* ZTrust supports the following as second factor authentication:
  * Push Notification
  * QR Code
  * NFC
  * Email OTP
  * TOTP
  * Biometric

**Prerequisites**

* User needs to be present in realm where 2FA is to be configured&#x20;
* For Push Notification, NFC and QR
  * Admin needs to configure [**RabbitMQ**](https://ztrust.gitbook.io/ztrust-documentation/user-manual-ztrust-v4.1/admin-manual/rabbitmq-configuration) in the Realm settings.
  * Users need to&#x20;
    * Install **ZTrust Authenticator app** in their mobile device.
    * Set their mobile device as a primary device.
* For TOTP
  * Users need to install **ZTrust Authenticator app** in their mobile device.
* For Email OTP
  * Email ID needs to be configured in the user details.
* For Biometric
  * Users first need to register their biometric details with ZTrust.

**Configuration**&#x20;

1. Click on **Authentication** in the sidebar.<br>

   <figure><img src="/files/5o3ZZXRI23XFp71TVaZ2" alt=""><figcaption><p>Fig. 4.12.10.a: Navingating to Authentication section</p></figcaption></figure>

2. Click on the **kebab menu (three dots)** on the right side of the browser flow. Select **Duplicate**. A popup will appear.<br>

   <figure><img src="/files/iOMZWshT3B6tzGPiMi4B" alt=""><figcaption><p>Fig 4.12.10.b: Duplicating the existing browser flow</p></figcaption></figure>

3. Provide a **Name** for the flow, "2FA Flow". Click **Duplicate**. You will be redirected to the new flow configuration.<br>

   <figure><img src="/files/DxXDdDqV7f5ao6vi9ZYD" alt=""><figcaption><p>Fig 4.12.10.c: Giving a name to the new browser flow for 2FA login</p></figcaption></figure>

   <figure><img src="/files/mxFy325Kj5DbFyOoBpxx" alt=""><figcaption><p>Fig 4.12.10.d: Duplicated browser flow configuration page for 2FA login</p></figcaption></figure>

4. Delete everything under **2FA Flow forms**.<br>

   <figure><img src="/files/jkv7qh80ZTJ5yagLcywI" alt=""><figcaption><p>Fig 4.12.10.e: 2FA after browser flow configuration page before deleting executions</p></figcaption></figure>

5. Click on the **plus** icon on the right side of the **2FA Flow forms**. Select **Add Sub-flow**. A popup will appear.<br>

   <figure><img src="/files/dJ5530r175jTDYV57BF0" alt=""><figcaption><p>Fig 4.12.10.f: Proceeding to add a new sub-flow to 2FA login flow</p></figcaption></figure>

6. Provide a **Name** for the sub-flow, "Username Password flow". Click **Add**.<br>

   <figure><img src="/files/q1enIvyOivfHVRxqjotB" alt=""><figcaption><p>Fig 4.12.10.g: Giving a name to the sub-flow for first-factor authentication</p></figcaption></figure>

7. Click on the **plus** icon on the right side of the **Username Password flow**. Select **Add Execution**. A popup will appear to select an execution.<br>

   <figure><img src="/files/6f4taP1UwWdS0Zi9lrLe" alt=""><figcaption><p>Fig 4.12.10.h: Proceeding to add a new execution to 2FA login flow</p></figcaption></figure>

8. Search for **Username Password Form**, select it and click **Add**.<br>

   <figure><img src="/files/yhavOclLnx6wnNaf1OWn" alt=""><figcaption><p>Fig 4.12.8.i: Select 'Username Password Form' execution to add</p></figcaption></figure>

9. Click on the **plus** icon on the right side of the **2FA Flow forms**. Select **Add Sub-flow**. A popup will appear.<br>

   <figure><img src="/files/4iSRkJvoVTZ4h9AH5ZGz" alt=""><figcaption><p>Fig 4.12.10.j: Giving a name to the sub-flow for second-factor authentication</p></figcaption></figure>

10. Provide a **Name** for the sub-flow, "Push Notification Flow". Click **Add**.<br>

    <figure><img src="/files/Q6q7S61lXGHkOfR2Lo4w" alt=""><figcaption><p>Fig 4.12.10.k: Giving a name to the sub-flow for second-factor authentication</p></figcaption></figure>

11. Click on the **plus** icon on the right side of the **Push Notification flow**. Select **Add Execution**. A popup will appear to select an execution.<br>

    <figure><img src="/files/AJMvqdWC9LrIkViO5Nw4" alt=""><figcaption><p>Fig 4.12.10.l: Proceeding to add a new execution to 2FA login flow</p></figcaption></figure>

12. Search for **Push Notification Authenticator**, select it and click **Add**.<br>

    <figure><img src="/files/PwNgw72BHOwVedw4ZoE8" alt=""><figcaption><p>Fig 4.12.8.i: Select 'Push Notification Authenticator' execution to add</p></figcaption></figure>

13. Click on the **settings menu (gear icon)** on the right side of the **Push Notification Authenticator**. A popup will appear to configure the push notification settings.<br>

    <figure><img src="/files/FrikvceMyXH3J8WbkkUP" alt=""><figcaption><p>Fig 4.12.10.j: Proceeding to configure 2FA login</p></figcaption></figure>

14. Provide an **Alias**. **Set Expires in (in seconds)** and click **Save**.<br>

    <figure><img src="/files/34Mq4wgqfd2CiakpdCN0" alt=""><figcaption><p>Fig 4.12.10.k: Configuring 2FA login</p></figcaption></figure>

15. Change **Requirement** of the **Push Notification Authenticator** from **Disabled** to **Required**.<br>

    <figure><img src="/files/80mcGbwDM2LWDbEJZDzG" alt=""><figcaption><p>Fig 4.12.10.l: Changing the 'Requirement' of second-factor in 2FA login</p></figcaption></figure>

16. Change **Requirement** of the **Push Notification flow** from **Disabled** to **Required**.<br>

    <figure><img src="/files/dTx7X763HjUkPrrJ8DaA" alt=""><figcaption><p>Fig 4.12.10.m: Changing the 'Requirement' of second-factor sub-flow in 2FA login</p></figcaption></figure>

17. Change **Requirement** of the **Username Password flow** from **Disabled** to **Required**.<br>

    <figure><img src="/files/PEpGkIhYznGiVLhIOvKU" alt=""><figcaption><p>Fig 4.12.10.n: Changing the 'Requirement' of first-factor sub-flow in 2FA login</p></figcaption></figure>

18. Click on the **Actions**, on the top right of the page, and then **Bind flow**. A popup will appear.<br>

    <figure><img src="/files/WXteWCUDbJ1hNsgX59aN" alt=""><figcaption><p>Fig 4.12.10.o: Proceeding to bind the 2FA login flow</p></figcaption></figure>

19. Select the **Browser flow** as the **binding type** and click **Save**.<br>

    <figure><img src="/files/Z9YOnmbtdAYbR1upkZl6" alt=""><figcaption><p>Fig 4.12.10.p: Selecting a flow to bind 2FA login to</p></figcaption></figure>

Two-factor authentication with **Username, password** and **Push Notification** is now enabled.
