← Back
Editing: two_factor-auth.html
<!DOCTYPE html> <html class="writer-html5" lang="en" data-content_root="../"> <head> <meta charset="utf-8" /> <meta name="readthedocs-addons-api-version" content="1"><meta name="viewport" content="width=device-width, initial-scale=1" /> <meta name="viewport" content="width=device-width, initial-scale=1.0" /> <title>Two-factor authentication — Nextcloud latest Administration Manual latest documentation</title> <link rel="stylesheet" type="text/css" href="../_static/pygments.css?v=b86133f3" /> <link rel="stylesheet" type="text/css" href="../_static/css/theme.css?v=e59714d7" /> <link rel="stylesheet" type="text/css" href="../_static/copybutton.css?v=76b2166b" /> <link rel="stylesheet" type="text/css" href="../_static/custom.css?v=8ff6e0db" /> <link rel="stylesheet" type="text/css" href="../_static/dark_mode_css/general.css?v=c0a7eb24" /> <link rel="stylesheet" type="text/css" href="../_static/dark_mode_css/dark.css?v=70edf1c7" /> <link rel="canonical" href="https://docs.nextcloud.com/server/stable/admin_manual/configuration_user/two_factor-auth.html" /> <script src="../_static/jquery.js?v=5d32c60e"></script> <script src="../_static/_sphinx_javascript_frameworks_compat.js?v=2cd50e6c"></script> <script src="../_static/documentation_options.js?v=a49d5d77"></script> <script src="../_static/doctools.js?v=9bcbadda"></script> <script src="../_static/sphinx_highlight.js?v=dc90522c"></script> <script src="../_static/clipboard.min.js?v=a7894cd8"></script> <script src="../_static/copybutton.js?v=f281be69"></script> <script src="../_static/dark_mode_js/default_light.js?v=c2e647ce"></script> <script src="../_static/dark_mode_js/theme_switcher.js?v=358d3910"></script> <script src="../_static/js/theme.js"></script> <script src="../_static/js/versions.js"></script> <link rel="index" title="Index" href="../genindex.html" /> <link rel="search" title="Search" href="../search.html" /> <link rel="next" title="User authentication with LDAP" href="user_auth_ldap.html" /> <link rel="prev" title="Authentication" href="authentication.html" /> </head> <body class="wy-body-for-nav"> <div class="wy-grid-for-nav"> <nav data-toggle="wy-nav-shift" class="wy-nav-side"> <div class="wy-side-scroll"> <div class="wy-side-nav-search" > <a href="../contents.html"> <img src="../_static/logo-white.png" class="logo" alt="Logo"/> </a> <div class="switch-menus"> <div class="version-switch"></div> <div class="language-switch"></div> </div> <div role="search"> <form id="rtd-search-form" class="wy-form" action="../search.html" method="get"> <input type="text" name="q" placeholder="Search docs" aria-label="Search docs" /> <input type="hidden" name="check_keywords" value="yes" /> <input type="hidden" name="area" value="default" /> </form> </div> </div><div class="wy-menu wy-menu-vertical" data-spy="affix" role="navigation" aria-label="Navigation menu"> <p class="caption" role="heading"><span class="caption-text">Getting Started</span></p> <ul> <li class="toctree-l1"><a class="reference internal" href="../index.html">Introduction</a></li> <li class="toctree-l1"><a class="reference internal" href="../release_schedule.html">Maintenance and release schedule</a></li> <li class="toctree-l1"><a class="reference internal" href="../gdpr/index.html">GDPR-compliance</a></li> <li class="toctree-l1"><a class="reference internal" href="../declarations/index.html">Declarations</a></li> </ul> <p class="caption" role="heading"><span class="caption-text">Release notes</span></p> <ul> <li class="toctree-l1"><a class="reference internal" href="../release_notes/index.html">Critical changes</a></li> </ul> <p class="caption" role="heading"><span class="caption-text">Installation</span></p> <ul> <li class="toctree-l1"><a class="reference internal" href="../installation/index.html">Installation and server configuration</a></li> <li class="toctree-l1"><a class="reference internal" href="../configuration_database/index.html">Database configuration</a></li> </ul> <p class="caption" role="heading"><span class="caption-text">Configuration</span></p> <ul> <li class="toctree-l1"><a class="reference internal" href="../configuration_server/index.html">Nextcloud configuration</a></li> <li class="toctree-l1"><a class="reference internal" href="../occ_command.html">Using the occ command</a></li> <li class="toctree-l1"><a class="reference internal" href="../reference/index.html">Reference management</a></li> <li class="toctree-l1"><a class="reference internal" href="../webhook_listeners/index.html">Webhook Listeners</a></li> <li class="toctree-l1"><a class="reference internal" href="../windmill_workflows/index.html">Windmill Workflows</a></li> </ul> <p class="caption" role="heading"><span class="caption-text">Files</span></p> <ul> <li class="toctree-l1"><a class="reference internal" href="../configuration_files/index.html">File sharing and management</a></li> <li class="toctree-l1"><a class="reference internal" href="../file_workflows/index.html">Flow</a></li> <li class="toctree-l1"><a class="reference internal" href="../configuration_mimetypes/index.html">Mimetypes management</a></li> </ul> <p class="caption" role="heading"><span class="caption-text">Apps</span></p> <ul> <li class="toctree-l1"><a class="reference internal" href="../apps_management.html">Apps management</a></li> <li class="toctree-l1"><a class="reference internal" href="../exapps_management/index.html">ExApps management</a></li> <li class="toctree-l1"><a class="reference internal" href="../ai/index.html">Artificial Intelligence</a></li> </ul> <p class="caption" role="heading"><span class="caption-text">Users</span></p> <ul class="current"> <li class="toctree-l1 current"><a class="reference internal" href="index.html">User management</a><ul class="current"> <li class="toctree-l2"><a class="reference internal" href="user_configuration.html">User management</a></li> <li class="toctree-l2"><a class="reference internal" href="reset_admin_password.html">Resetting a lost admin password</a></li> <li class="toctree-l2"><a class="reference internal" href="reset_user_password.html">Resetting a user password</a></li> <li class="toctree-l2"><a class="reference internal" href="user_password_policy.html">User password policy</a></li> <li class="toctree-l2"><a class="reference internal" href="authentication.html">Authentication</a></li> <li class="toctree-l2 current"><a class="current reference internal" href="#">Two-factor authentication</a><ul> <li class="toctree-l3"><a class="reference internal" href="#enabling-two-factor-authentication">Enabling two-factor authentication</a></li> <li class="toctree-l3"><a class="reference internal" href="#enforcing-two-factor-authentication">Enforcing two-factor authentication</a></li> <li class="toctree-l3"><a class="reference internal" href="#provider-removal">Provider removal</a></li> <li class="toctree-l3"><a class="reference internal" href="#disabling-two-factor-authentication">Disabling two-factor authentication</a></li> </ul> </li> <li class="toctree-l2"><a class="reference internal" href="user_auth_ldap.html">User authentication with LDAP</a></li> <li class="toctree-l2"><a class="reference internal" href="user_auth_ldap_cleanup.html">LDAP user cleanup</a></li> <li class="toctree-l2"><a class="reference internal" href="user_auth_ldap_api.html">The LDAP configuration API</a></li> <li class="toctree-l2"><a class="reference internal" href="user_provisioning_api.html">User provisioning API</a></li> <li class="toctree-l2"><a class="reference internal" href="profile_configuration.html">Profile configuration</a></li> <li class="toctree-l2"><a class="reference internal" href="user_auth_oidc.html">User authentication with OpenID Connect</a></li> </ul> </li> <li class="toctree-l1"><a class="reference internal" href="../desktop/index.html">Desktop Clients</a></li> </ul> <p class="caption" role="heading"><span class="caption-text">Groupware</span></p> <ul> <li class="toctree-l1"><a class="reference internal" href="../groupware/index.html">Groupware</a></li> </ul> <p class="caption" role="heading"><span class="caption-text">Office</span></p> <ul> <li class="toctree-l1"><a class="reference internal" href="../office/index.html">Office</a></li> </ul> <p class="caption" role="heading"><span class="caption-text">Maintenance</span></p> <ul> <li class="toctree-l1"><a class="reference internal" href="../configuration_monitoring/index.html">Monitoring</a></li> <li class="toctree-l1"><a class="reference internal" href="../maintenance/index.html">Maintenance</a></li> <li class="toctree-l1"><a class="reference internal" href="../issues/index.html">Issues and troubleshooting</a></li> </ul> <p class="caption" role="heading"><span class="caption-text">Links</span></p> <ul> <li class="toctree-l1"><a class="reference external" href="https://help.nextcloud.com/">Community Help Forum</a></li> <li class="toctree-l1"><a class="reference external" href="https://docs.nextcloud.com/">User Manuals</a></li> <li class="toctree-l1"><a class="reference external" href="https://docs.nextcloud.com/">Developer Manuals</a></li> <li class="toctree-l1"><a class="reference external" href="https://nextcloud.com/install/">Download</a></li> <li class="toctree-l1"><a class="reference external" href="https://apps.nextcloud.com">App Store</a></li> <li class="toctree-l1"><a class="reference external" href="https://help.nextcloud.com/t/translation-knowledge-valid-for-the-entire-nextcloud-project-wiki/51550">Translations</a></li> <li class="toctree-l1"><a class="reference external" href="https://github.com/nextcloud/">GitHub</a></li> <li class="toctree-l1"><a class="reference external" href="https://github.com/nextcloud/server/wiki/Maintenance-and-Release-Schedule">Supported versions</a></li> <li class="toctree-l1"><a class="reference external" href="https://nextcloud.com/enterprise/">Nextcloud Enterprise</a></li> <li class="toctree-l1"><a class="reference external" href="https://github.com/nextcloud/server/blob/master/COPYING-README">License</a></li> <li class="toctree-l1"><a class="reference external" href="https://nextcloud.com/">Nextcloud GmbH</a></li> </ul> </div> </div> </nav> <section data-toggle="wy-nav-shift" class="wy-nav-content-wrap"><nav class="wy-nav-top" aria-label="Mobile navigation menu" > <i data-toggle="wy-nav-top" class="fa fa-bars"></i> <a href="../contents.html">Nextcloud latest Administration Manual</a> </nav> <div class="wy-nav-content"> <div class="rst-content style-external-links"> <div role="navigation" aria-label="Page navigation"> <ul class="wy-breadcrumbs"> <li><a href="../contents.html" class="icon icon-home" aria-label="Home"></a></li> <li class="breadcrumb-item"><a href="index.html">User management</a></li> <li class="breadcrumb-item active">Two-factor authentication</li> <li class="wy-breadcrumbs-aside"> <a href="https://github.com/nextcloud/documentation/edit/master/admin_manual/configuration_user/two_factor-auth.rst" class="fa fa-github"> Edit on GitHub</a> </li> </ul> <hr/> </div> <div role="main" class="document" itemscope="itemscope" itemtype="http://schema.org/Article"> <div itemprop="articleBody"> <section id="two-factor-authentication"> <span id="two-factor-auth"></span><h1>Two-factor authentication<a class="headerlink" href="#two-factor-authentication" title="Link to this heading"></a></h1> <p>Two-factor authentication adds an additional layer of security to user accounts. In order to log in on an account when two-factor authentication (2FA) enabled, you must provide both the login password and another factor.</p> <p>To use 2FA two things must happen:</p> <ul class="simple"> <li><p>At least one 2FA provider must be enabled by the administrator.</p></li> <li><p>A user must activate 2FA on their account (or) the administrator must enforce the use of 2FA.</p></li> </ul> <p>Both steps are described below.</p> <section id="enabling-two-factor-authentication"> <h2>Enabling two-factor authentication<a class="headerlink" href="#enabling-two-factor-authentication" title="Link to this heading"></a></h2> <p>2FA in Nextcloud is pluggable, meaning that various 2FA providers can be used to support different types of factors. Three providers are automatically installed (but may need to be enabled):</p> <p><strong>Two-Factor TOTP Provider</strong></p> <ul class="simple"> <li><p>A 2FA factor provider that enables the use of a <a class="reference external" href="https://en.wikipedia.org/wiki/Time-based_One-time_Password_Algorithm">TOTP</a> (RFC 6238) app installed on a phone (or other device) to be used as the secondary factor</p></li> <li><p>Compatible with any RFC 6238 compliant TOTP client app (such as <a class="reference external" href="https://github.com/beemdevelopment/aegis">Aegis</a> or Google Authenticator).</p></li> <li><p>Disabled by default. Go to <em>Apps->Disabled apps</em> and find <em>Two-Factor TOTP Provider</em> to enable this factor.</p></li> </ul> <p><strong>Two-Factor Authentication via Nextcloud notifications</strong></p> <ul class="simple"> <li><p>A 2FA factor provider that enables the use of a logged in device as the secondary factor.</p></li> <li><p>Disabled by default. Go to <em>Apps->Disabled apps</em> and find <em>Two-Factor Authentication via Nextcloud notification</em> to enable this factor.</p></li> </ul> <p><strong>Two-Factor Backup Codes</strong></p> <ul class="simple"> <li><p>A special 2FA factor provider enables users to generate backup codes provider.</p></li> <li><p>Facilitates recovery of access if a a 2FA device is unavailable (i.e. gets stolen or is not working).</p></li> <li><p>Generates ten backup codes (which can, of course, only be use once).</p></li> <li><p>Always enabled.</p></li> </ul> <p>Other 2FA providers may be found in the App Store.</p> <figure class="align-default"> <img alt="../_images/2fa-app-install.png" src="../_images/2fa-app-install.png" /> </figure> <p>Developers can also <a class="reference external" href="https://docs.nextcloud.com/server/33/developer_manual/digging_deeper/two-factor-provider.html">implement new two-factor provider apps</a>.</p> </section> <section id="enforcing-two-factor-authentication"> <h2>Enforcing two-factor authentication<a class="headerlink" href="#enforcing-two-factor-authentication" title="Link to this heading"></a></h2> <p>By default 2FA is <em>optional</em>, hence users are given the choice whether to enable it for their account <a class="reference external" href="https://docs.nextcloud.com/server/33/user_manual/en/user_2fa.html">under their personal settings</a>. Admins may, however, enforce the use of 2FA.</p> <p>Enforcement is possible system-wide (all users) or for selected groups only. Select groups can also be excluded from 2FA requirements.</p> <p>These settings can be found under <em>Administration Settings->Security</em>.</p> <figure class="align-default"> <img alt="../_images/2fa-admin-settings.png" src="../_images/2fa-admin-settings.png" /> </figure> <p>When groups are selected/excluded, they use the following logic to determine if a user has 2FA enforced:</p> <ul class="simple"> <li><p>If no groups are selected, 2FA is enabled for everyone except members of the excluded groups</p></li> <li><p>If groups are selected, 2FA is enabled for all members of these. If a user is both in a selected <em>and</em> excluded group, the selected takes precedence and 2FA is enforced.</p></li> </ul> </section> <section id="provider-removal"> <h2>Provider removal<a class="headerlink" href="#provider-removal" title="Link to this heading"></a></h2> <p>Nextcloud keeps records about the enabled two-factor authentication providers of every user. If a provider is simply removed/<a class="reference internal" href="../occ_command.html#apps-commands-label"><span class="std std-ref">disabled</span></a>, Nextcloud will still consider the provider active for the user at login and show a warning like <em>Could not load at least one of your enabled two-factor auth methods</em>.</p> <p>The associations of removed providers can be cleaned up via <a class="reference internal" href="../occ_command.html#occ"><span class="std std-ref">occ</span></a>:</p> <div class="highlight-default notranslate"><div class="highlight"><pre><span></span><span class="n">sudo</span> <span class="o">-</span><span class="n">E</span> <span class="o">-</span><span class="n">u</span> <span class="n">www</span><span class="o">-</span><span class="n">data</span> <span class="n">php</span> <span class="n">occ</span> <span class="n">twofactorauth</span><span class="p">:</span><span class="n">cleanup</span> <span class="o"><</span><span class="n">provider_id</span><span class="o">></span> </pre></div> </div> <div class="admonition warning"> <p class="admonition-title">Warning</p> <p>This operation is irreversible. Only run it for providers you do not intend to enable again as then you have to setup the configuration for all users from scratch.</p> </div> </section> <section id="disabling-two-factor-authentication"> <h2>Disabling two-factor authentication<a class="headerlink" href="#disabling-two-factor-authentication" title="Link to this heading"></a></h2> <p>Two-factor providers can be disabled via <a class="reference internal" href="../occ_command.html#occ"><span class="std std-ref">occ</span></a>:</p> <div class="highlight-default notranslate"><div class="highlight"><pre><span></span><span class="n">sudo</span> <span class="o">-</span><span class="n">E</span> <span class="o">-</span><span class="n">u</span> <span class="n">www</span><span class="o">-</span><span class="n">data</span> <span class="n">php</span> <span class="n">occ</span> <span class="n">twofactorauth</span><span class="p">:</span><span class="n">disable</span> <span class="o"><</span><span class="n">uid</span><span class="o">></span> <span class="o"><</span><span class="n">provider_id</span><span class="o">></span> </pre></div> </div> <p>This can be useful if the user forgot or lost their second factor. Afterwards users are free to enable this provider again via their personal settings.</p> <div class="admonition note"> <p class="admonition-title">Note</p> <p>This operation has to be supported by the provider. If this support is missing, Nextcloud will abort and show an error.</p> </div> <p>It is also possible to check the current two-factor user status via <a class="reference internal" href="../occ_command.html#occ"><span class="std std-ref">occ</span></a>:</p> <div class="highlight-default notranslate"><div class="highlight"><pre><span></span><span class="n">sudo</span> <span class="o">-</span><span class="n">E</span> <span class="o">-</span><span class="n">u</span> <span class="n">www</span><span class="o">-</span><span class="n">data</span> <span class="n">php</span> <span class="n">occ</span> <span class="n">twofactorauth</span><span class="p">:</span><span class="n">state</span> <span class="o"><</span><span class="n">uid</span><span class="o">></span> </pre></div> </div> </section> </section> </div> </div> <footer><div class="rst-footer-buttons" role="navigation" aria-label="Footer"> <a href="authentication.html" class="btn btn-neutral float-left" title="Authentication" accesskey="p" rel="prev"><span class="fa fa-arrow-circle-left" aria-hidden="true"></span> Previous</a> <a href="user_auth_ldap.html" class="btn btn-neutral float-right" title="User authentication with LDAP" accesskey="n" rel="next">Next <span class="fa fa-arrow-circle-right" aria-hidden="true"></span></a> </div> <hr/> <div role="contentinfo"> <p>© Copyright 2016-2026 Nextcloud GmbH and Nextcloud contributors.</p> </div> </footer> </div> </div> </section> </div> <div class="rst-versions" data-toggle="rst-versions" role="note" aria-label="versions"> <span class="rst-current-version" data-toggle="rst-current-version"> ☁️ latest <span class="fa fa-caret-down"></span> </span> <div class="rst-other-versions"> <dl> <dt>☁️ Versions</dt> <dd style="width: 32%"> <a href="https://docs.nextcloud.com/server/latest/admin_manual" style="color: var(--dark-link-color);" > latest </a> </dd> <dd style="width: 32%"> <a href="https://docs.nextcloud.com/server/stable/admin_manual" > stable </a> </dd> <dd style="width: 32%"> <a href="https://docs.nextcloud.com/server/32/admin_manual" > 32 </a> </dd> <dd style="width: 32%"> <a href="https://docs.nextcloud.com/server/31/admin_manual" > 31 </a> </dd> </dl> </div> </div> <script> jQuery(function () { SphinxRtdTheme.Navigation.enable(true); }); </script> </body> </html>
Save File
Cancel