# Multifactor Authentication

**URL:** https://pug.phocassoftware.com/t/multifactor-authentication/1691
**Category:** Product Ideas
**Created:** [August 13, 2020, 7:50pm UTC](https://pug.phocassoftware.com/t/multifactor-authentication/1691 "2020-08-13T19:50:03Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![ECCOit](https://avatars.discourse-cdn.com/v4/letter/e/e56c9b/32.png) [@ECCOit](https://pug.phocassoftware.com/u/ECCOit)
#### Post date: [August 13, 2020, 7:50pm UTC](https://pug.phocassoftware.com/t/multifactor-authentication/1691/1 "2020-08-13T19:50:03Z")

</div>

I’d like to see multi-factor authentication implemented as an option for Phocas logins. Even though our data is read-only, the saved favorites, dashboards, etc. are modifiable. At the very least, it should be require for users with admin permissions.

We will be updating our password policy for Phocas logins but it would be nice to have the option of MFA.

Thanks!  
Austin

---

<div class="post-metadata">

### Author: ![rc\_h](https://avatars.discourse-cdn.com/v4/letter/r/71c47a/32.png) [@rc\_h](https://pug.phocassoftware.com/u/rc_h)
#### Post date: [May 4, 2021, 6:41pm UTC](https://pug.phocassoftware.com/t/multifactor-authentication/1691/2 "2021-05-04T18:41:51Z")

</div>

Agree. It’s not only the saved favorites and dashboards, the data in Phocas are confidential and need to be protected by the extra layer of security provided by Multifactor authentication.

---

<div class="post-metadata">

### Author: ![Jordon](https://avatars.discourse-cdn.com/v4/letter/j/d2c977/32.png) [@Jordon](https://pug.phocassoftware.com/u/Jordon)
#### Post date: [March 21, 2022, 9:58pm UTC](https://pug.phocassoftware.com/t/multifactor-authentication/1691/3 "2022-03-21T21:58:58Z")

</div>

How is this not already available in 2022 with the current cyber security environment???

---

<div class="post-metadata">

### Author: ![alex](https://avatars.discourse-cdn.com/v4/letter/a/db5fbb/32.png) [@alex](https://pug.phocassoftware.com/u/alex)
#### Post date: [November 3, 2022, 3:17pm UTC](https://pug.phocassoftware.com/t/multifactor-authentication/1691/4 "2022-11-03T15:17:03Z")

</div>

As a fairly new Phocas user I was shocked to see there’s no MFA. It looks like it’s been requested for a while. It would be great to have an update on the status of this

---

<div class="post-metadata">

### Author: ![sam2005](https://avatars.discourse-cdn.com/v4/letter/s/7feea3/32.png) [@sam2005](https://pug.phocassoftware.com/u/sam2005)
#### Post date: [March 22, 2023, 5:29pm UTC](https://pug.phocassoftware.com/t/multifactor-authentication/1691/5 "2023-03-22T17:29:54Z")

</div>

Just adding another user here to wonder why MFA isn’t enabled yet. MFA is configured to join the user group, but not in the actual application? This needs to get moved up on the priority list.

---

<div class="post-metadata">

### Author: ![aaron.roma](https://sea1.discourse-cdn.com/flex015/user_avatar/pug.phocassoftware.com/aaron.roma/32/285_2.png) [@aaron.roma](https://pug.phocassoftware.com/u/aaron.roma)
#### Post date: [April 2, 2023, 1:15am UTC](https://pug.phocassoftware.com/t/multifactor-authentication/1691/6 "2023-04-02T01:15:47Z")

</div>

Just wanted to add my voice here too. Really wish Phocas would get something implemented here. We have a bit of a workaround for now. We’re using a SAML provider for logins, and this SAML provider uses MFA. We set the users’ Phocas password to a ramdom password. If I had a way to disable the “local” login for users, and force use of the SAML provider, this would work for me.

Ironically, It’s been a while since I’ve posted on here. I was forced to setup MFA on my PUG login so I could login and post about lack of support for MFA in Phocas.
