---
title: "Configuring Multi-Factor Authentication for Domain Users"
canonical: "https://docs.infoblox.com/space/BloxOneCloud/35398479/Configuring%20Multi-Factor%20Authentication%20for%20Domain%20Users"
format: markdown
---
<span style="color: #000000">If you have activated MFA (multi-factor authentication) for a domain, all users with an email address that matches the domain name can have an individual configuration for multi-factor authentication.</span>

> ⚠️ **Note**
> ⚠️ 
> ⚠️ You can activate MFA only if 3rd party IdP is deactivated. For information about deactivating 3rd party IdP, see [*Deactivating 3rd Party IdP Authentication*](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35464005).

<span style="color: #000000">You can perform the following multi-factor authentication for individual domain users:</span>

- <span style="color: #000000">Resetting MFA Enrollment</span>
- <span style="color: #000000">Activating MFA </span>
- <span style="color: #000000">Deactivating MFA </span>

<span style="color: #000000">Changes made to these options are reflected in the </span>*<span style="color: #000000">MFA</span>*<span style="color: #000000"> column of the </span>*<span style="color: #000000">Domain Users</span>*<span style="color: #000000"> table. This option is related to </span>**<span style="color: #000000">MFA Configuration</span>**<span style="color: #000000"> in the </span>**<span style="color: #000000">Authentication</span>**<span style="color: #000000"> tab, which configures MFA for all users in a selected domain. Note that if a domain is configured with a 3rd party IdP, all users with a matching email domain will have their MFA status deactivated.</span>

# <span style="color: #000000">Resetting MFA Enrollment</span>

<span style="color: #000000">You can reset multi-factor enrollment for specific users. When you reset enrollment for a user, the user must reconfigure multi-factor authentication when logging in to Infoblox services the next time.</span>

<span style="color: #000000">To reset MFA enrollment for a domain user, complete the following:</span>

1. <span style="color: #000000">Log in to the Infoblox SSO Portal at </span>[<span style="color: #000000">https://sso.infoblox.com/</span>](https://sso.infoblox.com/)<span style="color: #000000">.</span>
2. <span style="color: #000000">Click </span>**<span style="color: #000000">User Access</span>**<span style="color: #000000"> -> </span>**<span style="color: #000000">Domain Users</span>**<span style="color: #000000"> tab.</span>
3. <span style="color: #000000">Select a domain user in the table, and then click </span>**<span style="color: #000000">Reset MFA Enrollment</span>**<span style="color: #000000"> from the </span>**<span style="color: #000000">MFA</span>**<span style="color: #000000"> drop-down menu. </span>

> ⚠️ **Note**
> ⚠️ 
> ⚠️ <span style="color: #000000">You can reset the MFA enrollment for a user only if MFA is </span>**<span style="color: #000000">Enabled</span>**<span style="color: #000000"> for the selected user.</span>

# <span style="color: #000000">Activating MFA</span>

<span style="color: #000000">You can activate multi-factor authentication for specific users. When you activate MFA for a user, the user must configure multi-factor authentication during the next login to Infoblox services.</span>

<span style="color: #000000">To activate MFA for a domain user, complete the following:</span>

1. <span style="color: #000000">Log in to the Infoblox SSO Portal.</span>
2. <span style="color: #000000">Click </span>**<span style="color: #000000">User Access</span>**<span style="color: #000000"> -> </span>**<span style="color: #000000">Domain Users</span>**<span style="color: #000000"> tab.</span>
3. <span style="color: #000000">Select a domain user in the table, and then click </span>**<span style="color: #000000">Activate MFA</span>**<span style="color: #000000"> from the </span>**<span style="color: #000000">MFA</span>**<span style="color: #000000"> drop-down menu. </span>

# <span style="color: #000000">Deactivating MFA</span>

<span style="color: #000000">You can deactivate multi-factor enrollment for specific users. When you deactivate MFA for a user, the user is no longer authenticated via MFA.</span>

<span style="color: #000000">To deactivate MFA for a domain user, complete the following:</span>

1. <span style="color: #000000">Log in to the Infoblox SSO Portal.</span>
2. <span style="color: #000000">Click </span>**<span style="color: #000000">User Access</span>**<span style="color: #000000"> -> </span>**<span style="color: #000000">Domain Users</span>**<span style="color: #000000"> tab.</span>
3. <span style="color: #000000">Select a domain user in the table, and then click </span>**<span style="color: #000000">Deactivate MFA</span>**<span style="color: #000000"> from the </span>**<span style="color: #000000">MFA</span>**<span style="color: #000000"> drop-down menu. </span>

<span style="color: #000000">If you have activated MFA (multi-factor authentication) for a domain, all users with an email address that matches the domain name can have an individual configuration for multi-factor authentication.</span>

> ⚠️ **Note**
> ⚠️ 
> ⚠️ You can activate MFA only if 3rd party IdP is deactivated. For information about deactivating 3rd party IdP, see [*Deactivating 3rd Party IdP Authentication*](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35464005).

<span style="color: #000000">You can perform the following multi-factor authentication for individual domain users:</span>

- [<span style="color: #000000">*Resetting MFA Enrollment*</span>](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35398520/Resetting+User+Enrollment)
- [<span style="color: #000000">*Activating MFA*</span>](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35398479/Configuring+Multi-Factor+Authentication+for+Domain+Users)<span style="color: #000000">* *</span>
- [<span style="color: #000000">*Deactivating 3rd Party IdP Authentication*</span>](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35464005)<span style="color: #000000">* *</span>

<span style="color: #000000">Changes made to these options are reflected in the </span>*<span style="color: #000000">MFA</span>*<span style="color: #000000"> column of the </span>*<span style="color: #000000">Domain Users</span>*<span style="color: #000000"> table. This option is related to </span>**<span style="color: #000000">MFA Configuration</span>**<span style="color: #000000"> in the </span>**<span style="color: #000000">Authentication</span>**<span style="color: #000000"> tab, which configures MFA for all users in a selected domain. Note that if a domain is configured with a 3rd party IdP, all users with a matching email domain will have their MFA status deactivated.</span>

# <span style="color: #000000">Resetting MFA Enrollment</span>

<span style="color: #000000">You can reset multi-factor enrollment for specific users. When you reset enrollment for a user, the user must reconfigure multi-factor authentication when logging in to Infoblox services the next time.</span>

<span style="color: #000000">To reset MFA enrollment for a domain user, complete the following:</span>

1. <span style="color: #000000">Log in to the Infoblox SSO Portal at </span>[<span style="color: #000000">https://sso.infoblox.com/</span>](https://sso.infoblox.com/)<span style="color: #000000">.</span>
2. <span style="color: #000000">Click </span>**<span style="color: #000000">User Access</span>**<span style="color: #000000"> -> </span>**<span style="color: #000000">Domain Users</span>**<span style="color: #000000"> tab.</span>
3. <span style="color: #000000">Select a domain user in the table, and then click </span>**<span style="color: #000000">Reset MFA Enrollment</span>**<span style="color: #000000"> from the </span>**<span style="color: #000000">MFA</span>**<span style="color: #000000"> drop-down menu. </span>

> ⚠️ **Note**
> ⚠️ 
> ⚠️ <span style="color: #000000">You can reset the MFA enrollment for a user only if MFA is </span>**<span style="color: #000000">Enabled</span>**<span style="color: #000000"> for the selected user.</span>

# <span style="color: #000000">Activating MFA</span>

<span style="color: #000000">You can activate multi-factor authentication for specific users. When you activate MFA for a user, the user must configure multi-factor authentication during the next login to Infoblox services.</span>

<span style="color: #000000">To activate MFA for a domain user, complete the following:</span>

1. <span style="color: #000000">Log in to the Infoblox SSO Portal.</span>
2. <span style="color: #000000">Click </span>**<span style="color: #000000">User Access</span>**<span style="color: #000000"> -> </span>**<span style="color: #000000">Domain Users</span>**<span style="color: #000000"> tab.</span>
3. <span style="color: #000000">Select a domain user in the table, and then click </span>**<span style="color: #000000">Activate MFA</span>**<span style="color: #000000"> from the </span>**<span style="color: #000000">MFA</span>**<span style="color: #000000"> drop-down menu. </span>

# <span style="color: #000000">Deactivating MFA</span>

<span style="color: #000000">You can deactivate multi-factor enrollment for specific users. When you deactivate MFA for a user, the user is no longer authenticated via MFA.</span>

<span style="color: #000000">To deactivate MFA for a domain user, complete the following:</span>

1. <span style="color: #000000">Log in to the Infoblox SSO Portal.</span>
2. <span style="color: #000000">Click </span>**<span style="color: #000000">User Access</span>**<span style="color: #000000"> -> </span>**<span style="color: #000000">Domain Users</span>**<span style="color: #000000"> tab.</span>
3. <span style="color: #000000">Select a domain user in the table, and then click </span>**<span style="color: #000000">Deactivate MFA</span>**<span style="color: #000000"> from the </span>**<span style="color: #000000">MFA</span>**<span style="color: #000000"> drop-down menu. </span>