Veritas NetBackup™ Appliance Commands Reference Guide
- Overview
- Appendix A. Main > Appliance commands
- Appendix B. Main > Manage > FibreChannel commands
- Appendix C. Main > Manage > HighAvailability commands
- Appendix D. Main > Manage > Libraries commands
- Appendix E. Main > Manage > Libraries > Advanced > ACS commands
- Appendix F. Main > Manage > License commands
- Appendix G. Main > Manage > MountPoints commands
- Appendix H. Main > Manage > NetBackup CLI commands
- Appendix I. Main > Manage > OpenStorage commands
- Appendix J. Main > Manage > Software commands
- Appendix K. Main > Manage > Storage commands
- Appendix L. Main > Manage > Tapes commands
- Appendix M. Main > Monitor commands
- Appendix N. Main > Network commands
- Appendix O. Main > Network > Security commands (DeviceCert)
- Appendix P. Main > Reports commands
- Appendix Q. Main > Settings commands
- Appendix R. Main > Settings > Alerts commands
- Appendix S. Main > Settings > Notifications view commands
- Appendix T. Main > Settings > Security commands
- Appendix U. Main > Support commands
Name
Main > Settings > Security > Authentication > MFA — Configure and manage multifactor authentication for all appliance users.
SYNOPSIS
Configure
Enforce
Reset
Show GlobalEnforcement
Show Key
Unconfigure
Description
Multifactor authentication requires users to verify their appliance login identity by means of a system-generated code that is required in addition to the standard login password.
When multifactor authentication is enabled, each time you log in to the appliance you enter your username and password as usual. Next, you are prompted through a remote device, such as a smartphone, to enter a second factor to verify your identity. When you open the app on your smartphone, it shows a unique 6-digit code that you must enter to complete the login.
Use the MFA command options to configure and manage multifactor authentication for all Active Directory (AD), LDAP, and local users. Any user can configure multifactor authentication for their user account.
Note:
You cannot use multifactor authentication if Smart Card configuration is enabled.
The following describes the command options under Authentication > MFA:
Note:
For NetBackupCLI users and no-role users, log in to the appliance and run the multifactor-authentication command, then run the following submenu commands.
- Configure
Use this command to configure and enable multifactor authentication for the current user. All appliance users including NetBackupCLI users and users with no role assignment can configure their own account. An administrator must configure the feature before any other users can configure multifactor authentication for their user accounts.
The following describes the configuration requirements for administrators:
Minimum of two administrator accounts - The appliance must have at least two administrator accounts before they can configure multifactor authentication for their user accounts. If only one administrator user account exists when another user tries to configure the feature, an error message appears to inform them to add another administrator user account.
Minimum of one NTP server - At least one NTP server must be configured and added before the first administrator can configure multifactor authentication for their user account. A message appears if an NTP server is needed.
Note:
The NTP server is typically configured when you perform the initial configuration on the appliance. If you did not configure an NTP server at that time, you must configure at least one NTP server with the Main > Network > NTPServer command.
After the above configurations are completed, all other appliance users can configure their user accounts.
The following describes configuration requirements for all users:
If multifactor authentication is configured but not enforced for all users (global enforcement), a user can configure their user account or clear their configuration at any time.
If multifactor authentication is configured and is also enforced for all users, a user can clear their user account configuration only within a defined grace period. The grace period default is 90 days. After the grace period has expired, the user is forced to configure their user account during login, but they cannot clear their account configuration.
NetBackupCLI and no-role users must log in to the appliance and run the MFA command, then run the Configure submenu command.
- Enforce
Use this command to enforce multifactor authentication for all appliance users. Note the following requirements:
Only an administrator can run this command.
To run this command, you must have at least two administrator accounts configured for multifactor authentication and at least one configured NTP server.
- Reset
Use this command to reset the multifactor authentication configuration for a user that is unable to log in. Only an administrator can reset the multifactor authentication configuration for a user.
- Show GlobalEnforcement
Use this command to check if multifactor authentication is enforced for all users.
- Show Key
Use this command to show the key and the QR code for the current user.
- Unconfigure
Use this command to clear the multifactor authentication configuration for the current user. If multifactor authentication is enforced for all users, users can clear their own configuration only within the 90-day grace period.