MFA for Windows Offline Client

What is a one sentence summary of your feature request?

Login into Offline Client with Username, Password and OTP

Please describe your idea in detail. What is your problem, why do you feel this idea is the best solution, etc.

Best Security for Login into Windows Offline Client to prevent unauthorized Access.

How do you currently solve the challenges you have by not having this feature?

No Solution available

2 Likes

We could use that aswell. @Netwrix what is your take on that?

1 Like

Would be great to get some Feedback. There ist another Idea with the same issue. (MFA for Offline Client - Password Secure / Ideas - Netwrix Community)
@Kristina.kaya

1 Like

Thanks so much for raising this idea! :raising_hands:

We can definitely see the value in adding an additional authentication factor when logging into the Offline Client!

Before we explore implementation approaches and priorities, we’d like to gather a bit more feedback from the community:

:small_blue_diamond: Would a second factor based solely on TOTP (e.g., codes from an authenticator app) work for your offline use cases? This is a common offline MFA method that does not require an active network connection once the shared secret is provisioned.

:small_blue_diamond: We’re also thinking it would be best to make offline second-factor optional, so teams that don’t need it aren’t forced to take additional steps… but we’d appreciate your input on that as well.

:speech_balloon: Any thoughts on TOTP usability in your environments, or other offline MFA methods you’d like to see? Open feedback and examples of your specific scenarios would be really helpful!

Cheers,
Sascha

Hi Sascha,

TOPT is the easiest way for us to protect the clients’ offline database from unauthorized access.

This feature can be optional for our purposes.

1 Like

Hello,

I am also strongly in favor of the offline database having an MFA option, preferably optional. For me, it is a very important security factor. Why can I secure the “normal” database with MFA but not the offline database? I have been waiting for this feature for 2 years… had it “wrapped up” with my supplier. :wink:

TOTP is fine for me.

I would be very happy about a prompt implementation. Thank you. :slight_smile:

2 Likes

Hi,

an optional TOTP would be nice and enough for most customers.

Hi Sascha,

any further thoughts?
@Sascha

An MFA would certainly make sense for the offline client!