> For the complete documentation index, see [llms.txt](https://ztrust.gitbook.io/ztrust-documentation/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ztrust.gitbook.io/ztrust-documentation/user-manual-ztrust-v4.1/4.-admin-manual/4.13-set-up-multi-factor-authentication/4.13.10-how-to-set-up-2fa-authentication.md).

# 4.13.10 How to set-up 2FA Authentication

This section helps admin to set-up two factor authentication flow for the end users.

*Two-Factor Authentication (2FA), in ZTrust, is a security process that requires users to provide two different forms of identification to access an account or system, such as a password and a push notification from the ZTrust Authenticator mobile application.*

## Use Case

* Admin able to configure the 2FA authentication flow.
* Users should be able to login by using the configured 2FA flow.
* ZTrust supports the following as first factor authentication:
  * Username Password
  * Push Notification
  * QR Code
  * Email OTP
* ZTrust supports the following as second factor authentication:
  * Push Notification
  * QR Code
  * NFC
  * Email OTP
  * TOTP
  * Biometric

**Prerequisites**

* User needs to be present in realm where 2FA is to be configured&#x20;
* For Push Notification, NFC and QR
  * Admin needs to configure [**RabbitMQ**](https://ztrust.gitbook.io/ztrust-documentation/user-manual-ztrust-v4.1/admin-manual/rabbitmq-configuration) in the Realm settings.
  * Users need to&#x20;
    * Install **ZTrust Authenticator app** in their mobile device.
    * Set their mobile device as a primary device.
* For TOTP
  * Users need to install **ZTrust Authenticator app** in their mobile device.
* For Email OTP
  * Email ID needs to be configured in the user details.
* For Biometric
  * Users first need to register their biometric details with ZTrust.

**Configuration**&#x20;

1. Click on **Authentication** in the sidebar.<br>

   <figure><img src="https://1778922777-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F3EUK5AUZv0UVaI5S0CTM%2Fuploads%2FfWrotZg8myTgiItKWZVV%2FScreenshot%202025-09-08%20221549.png?alt=media&amp;token=93bf33ee-a4fc-49f7-a599-87f0a432c054" alt=""><figcaption><p>Fig. 4.12.10.a: Navingating to Authentication section</p></figcaption></figure>

2. Click on the **kebab menu (three dots)** on the right side of the browser flow. Select **Duplicate**. A popup will appear.<br>

   <figure><img src="https://1778922777-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F3EUK5AUZv0UVaI5S0CTM%2Fuploads%2FOLyA54hffRp6Tb53vliS%2FScreenshot%202025-09-08%20223201.png?alt=media&amp;token=e4d486e7-508f-4c53-8c64-82cff6c83b44" alt=""><figcaption><p>Fig 4.12.10.b: Duplicating the existing browser flow</p></figcaption></figure>

3. Provide a **Name** for the flow, "2FA Flow". Click **Duplicate**. You will be redirected to the new flow configuration.<br>

   <figure><img src="https://1778922777-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F3EUK5AUZv0UVaI5S0CTM%2Fuploads%2FzzXV2A8zlZheV318xBAV%2Fimage.png?alt=media&amp;token=dc1ead7d-cb1a-4f2c-8df0-6670b5081de2" alt=""><figcaption><p>Fig 4.12.10.c: Giving a name to the new browser flow for 2FA login</p></figcaption></figure>

   <figure><img src="https://1778922777-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F3EUK5AUZv0UVaI5S0CTM%2Fuploads%2FtdVPEb0MU1g5whLiPlCx%2Fimage.png?alt=media&amp;token=3d08427e-f2b0-4cc1-9988-01f4c9c25baa" alt=""><figcaption><p>Fig 4.12.10.d: Duplicated browser flow configuration page for 2FA login</p></figcaption></figure>

4. Delete everything under **2FA Flow forms**.<br>

   <figure><img src="https://1778922777-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F3EUK5AUZv0UVaI5S0CTM%2Fuploads%2FpkvRzsJs7CfGMSKLnKHF%2Fimage.png?alt=media&amp;token=6b18af4c-12a9-45e5-8c63-cdf03172f644" alt=""><figcaption><p>Fig 4.12.10.e: 2FA after browser flow configuration page before deleting executions</p></figcaption></figure>

5. Click on the **plus** icon on the right side of the **2FA Flow forms**. Select **Add Sub-flow**. A popup will appear.<br>

   <figure><img src="https://1778922777-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F3EUK5AUZv0UVaI5S0CTM%2Fuploads%2FDWUaJXacxk79iGcqKfrq%2Fimage.png?alt=media&amp;token=27a6d1f0-2021-440f-89c1-c5f2b7cbab67" alt=""><figcaption><p>Fig 4.12.10.f: Proceeding to add a new sub-flow to 2FA login flow</p></figcaption></figure>

6. Provide a **Name** for the sub-flow, "Username Password flow". Click **Add**.<br>

   <figure><img src="https://1778922777-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F3EUK5AUZv0UVaI5S0CTM%2Fuploads%2FNGtUP95P6yxg6O0vsFbO%2Fimage.png?alt=media&amp;token=e943b50f-4b80-4763-991e-0ee58ac72a28" alt=""><figcaption><p>Fig 4.12.10.g: Giving a name to the sub-flow for first-factor authentication</p></figcaption></figure>

7. Click on the **plus** icon on the right side of the **Username Password flow**. Select **Add Execution**. A popup will appear to select an execution.<br>

   <figure><img src="https://1778922777-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F3EUK5AUZv0UVaI5S0CTM%2Fuploads%2F1BNtv4J6CTbxTr9YNJC9%2Fimage.png?alt=media&amp;token=389260f5-7c8a-451a-a82d-bf110dbe0c53" alt=""><figcaption><p>Fig 4.12.10.h: Proceeding to add a new execution to 2FA login flow</p></figcaption></figure>

8. Search for **Username Password Form**, select it and click **Add**.<br>

   <figure><img src="https://1778922777-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F3EUK5AUZv0UVaI5S0CTM%2Fuploads%2FS7bkpW4vzyQDI6Y9zHF0%2Fimage.png?alt=media&amp;token=588f0c5a-4f03-424e-85e1-596ed3139ad1" alt=""><figcaption><p>Fig 4.12.8.i: Select 'Username Password Form' execution to add</p></figcaption></figure>

9. Click on the **plus** icon on the right side of the **2FA Flow forms**. Select **Add Sub-flow**. A popup will appear.<br>

   <figure><img src="https://1778922777-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F3EUK5AUZv0UVaI5S0CTM%2Fuploads%2F5a51yWHRzcqCTeO8Unwc%2Fimage.png?alt=media&amp;token=cce023a2-7bb7-4087-aa12-2d897246d7b1" alt=""><figcaption><p>Fig 4.12.10.j: Giving a name to the sub-flow for second-factor authentication</p></figcaption></figure>

10. Provide a **Name** for the sub-flow, "Push Notification Flow". Click **Add**.<br>

    <figure><img src="https://1778922777-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F3EUK5AUZv0UVaI5S0CTM%2Fuploads%2FKxBz2xn96JnyZddS0tzc%2Fimage.png?alt=media&amp;token=d1a66377-41ef-4b8a-89c0-b9b0a0b0bffc" alt=""><figcaption><p>Fig 4.12.10.k: Giving a name to the sub-flow for second-factor authentication</p></figcaption></figure>

11. Click on the **plus** icon on the right side of the **Push Notification flow**. Select **Add Execution**. A popup will appear to select an execution.<br>

    <figure><img src="https://1778922777-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F3EUK5AUZv0UVaI5S0CTM%2Fuploads%2FsO1sTSoMAXHdvgY35fBP%2Fimage.png?alt=media&amp;token=b8982ac5-f231-4e07-bf48-758a2f1bea84" alt=""><figcaption><p>Fig 4.12.10.l: Proceeding to add a new execution to 2FA login flow</p></figcaption></figure>

12. Search for **Push Notification Authenticator**, select it and click **Add**.<br>

    <figure><img src="https://1778922777-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F3EUK5AUZv0UVaI5S0CTM%2Fuploads%2F3Cs9s703w021k8eMVgGv%2Fimage.png?alt=media&amp;token=26b4e325-c354-4546-9b77-fa3d265019f0" alt=""><figcaption><p>Fig 4.12.8.i: Select 'Push Notification Authenticator' execution to add</p></figcaption></figure>

13. Click on the **settings menu (gear icon)** on the right side of the **Push Notification Authenticator**. A popup will appear to configure the push notification settings.<br>

    <figure><img src="https://1778922777-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F3EUK5AUZv0UVaI5S0CTM%2Fuploads%2FWEIYpijqGCuSdeUzgavD%2Fimage.png?alt=media&amp;token=b7416a69-dac5-4fb2-a3da-bf69b8e0900b" alt=""><figcaption><p>Fig 4.12.10.j: Proceeding to configure 2FA login</p></figcaption></figure>

14. Provide an **Alias**. **Set Expires in (in seconds)** and click **Save**.<br>

    <figure><img src="https://1778922777-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F3EUK5AUZv0UVaI5S0CTM%2Fuploads%2FVVQS372L1xlg75E9yogb%2Fimage.png?alt=media&amp;token=d46aee66-d347-4bb1-96ed-ce29cf708693" alt=""><figcaption><p>Fig 4.12.10.k: Configuring 2FA login</p></figcaption></figure>

15. Change **Requirement** of the **Push Notification Authenticator** from **Disabled** to **Required**.<br>

    <figure><img src="https://1778922777-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F3EUK5AUZv0UVaI5S0CTM%2Fuploads%2Fn6kHMwPERzGVYR6CTcP7%2Fimage.png?alt=media&amp;token=8df93d2e-4fbe-4a53-92d0-85aef74c46f9" alt=""><figcaption><p>Fig 4.12.10.l: Changing the 'Requirement' of second-factor in 2FA login</p></figcaption></figure>

16. Change **Requirement** of the **Push Notification flow** from **Disabled** to **Required**.<br>

    <figure><img src="https://1778922777-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F3EUK5AUZv0UVaI5S0CTM%2Fuploads%2FlqNIfq1lWpLIllOVpVzG%2Fimage.png?alt=media&amp;token=13f1fda4-928d-455e-8562-6bbb62a30b3a" alt=""><figcaption><p>Fig 4.12.10.m: Changing the 'Requirement' of second-factor sub-flow in 2FA login</p></figcaption></figure>

17. Change **Requirement** of the **Username Password flow** from **Disabled** to **Required**.<br>

    <figure><img src="https://1778922777-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F3EUK5AUZv0UVaI5S0CTM%2Fuploads%2FDTRwySgVoyQ2PdBOsfpl%2Fimage.png?alt=media&amp;token=566ed20c-9398-4a9e-b835-6395244505ce" alt=""><figcaption><p>Fig 4.12.10.n: Changing the 'Requirement' of first-factor sub-flow in 2FA login</p></figcaption></figure>

18. Click on the **Actions**, on the top right of the page, and then **Bind flow**. A popup will appear.<br>

    <figure><img src="https://1778922777-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F3EUK5AUZv0UVaI5S0CTM%2Fuploads%2FlBONQb4Ylmgdu4IPQC4W%2Fimage.png?alt=media&amp;token=ca4e54d4-ef12-498e-b91c-7a1c1558990b" alt=""><figcaption><p>Fig 4.12.10.o: Proceeding to bind the 2FA login flow</p></figcaption></figure>

19. Select the **Browser flow** as the **binding type** and click **Save**.<br>

    <figure><img src="https://1778922777-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F3EUK5AUZv0UVaI5S0CTM%2Fuploads%2FwWTd613Tp70AIS71w7d0%2FScreenshot%202025-09-08%20230104.png?alt=media&amp;token=142b88d7-81f5-4794-a5b8-ef7e1cc7144d" alt=""><figcaption><p>Fig 4.12.10.p: Selecting a flow to bind 2FA login to</p></figcaption></figure>

Two-factor authentication with **Username, password** and **Push Notification** is now enabled.
