Multi-Factor Authentication
Multi-Factor Authentication (MFA
Multifactor Authentication - an electronic authentication method in which a user is granted access to a website or application only after successfully presenting two or more pieces of evidence (or factors) to an authentication mechanism.) is an additional layer of security for the Check Point Portal. With MFA, Check Point Portal users must use an authentication app
For information about MFA for MSSP
Managed Security Service Provider (MSSP) - An managed security service provider (MSSP) provides outsourced monitoring and management of security devices and systems. Common services include managed firewall, intrusion detection, virtual private network, vulnerability scanning and anti-viral services./Distributor child accounts, see Manage Accounts.
Organizations can configure and manage MFA as part of Single Sign-On (SSO
Single Sign-On (SSO) - A session/user authentication process that permits a user to enter one name and password in order to access multiple applications.) with an Identity Provider
A system entity that creates, maintains, and manages identity information for principals and also provides authentication services to relying applications within a federation or distributed network. Acronym: IdP or IDP.. For example, some organizations require MFA as part of user authentication through Microsoft Entra ID. Thus, Check Point Portal users who log in through Microsoft Entra ID authenticate themselves with MFA according to the policy configured by the organization's Microsoft Entra ID administrator.
Creating and Editing MFA Configurations for Your User Account
This video shows you how to configure MFA using an authenticator app.
Watch the Video
-
Download one of these authenticator applications to your mobile phone:
-
Google Authentication
-
Microsoft Authenticator
-
Authy
-
-
In the Check Point Portal, click your user avatar
in the upper-right corner and select Profile Settings. -
Select Sign-in Options.
-
In the Multi-Factor Authentication section, click Configure.
-
In the Secure your account window, select your country from the list.
-
Toggle the Enforce Multi-Factor Authentication switch to ON.
The Enforce Multi-Factor Authentication configuration wizard opens.
-
Follow the on-screen instructions to connect the authentication app to the Check Point Portal.
Note - If you did not verify your phone number in the Profile Settings window, you must verify it in the Multi-Factor Authentication configuration wizard.
-
If you want to require yourself to use MFA for all Check Point Portal accounts, keep the toggle on. If you want to use MFA only when a Primary Administrator of an account requires it, switch the toggle off.
-
Click Finish to close the wizard.
-
In the Check Point Portal, click your user avatar
and select Profile Settings. -
Select Sign-in Options.
-
In the Multi-Factor Authentication section, click Configure. The first MFA method is with an authenticator app. If this method is configured, you can verify your phone number as a second method.
-
In the Secure your account window, select your country from the list.
-
Enter your mobile phone number.
-
Click Send code.
Check Point sends an SMS to your phone with a six-digit code.
-
Enter the code in the Code field.
-
Click Verify code.
To configure a passkey, see Configuring a Passkey
If your organization uses SSO authentication and does not enable MFA as part of it, you can require yourself to use MFA every time you log in to the Check Point Portal. This is valid even when the Primary Administrator of the Check Point Portal account does not require MFA.
Use Case: A security administrator works for a Check Point MSSP to manage child accounts. One of the MSSP's customers does not require its own security administrators to use MFA. The MSSP's corporate policy requires MFA for all Check Point Portal logins.
Configuring Multi-Factor Authentication on your account:
-
Download one of these authenticator applications to your mobile device:
-
Google Authenticator
-
Microsoft Authenticator
-
Authy
-
-
In the Check Point Portal, click your user avatar
in the upper right. -
Select Profile Settings > Sign-in Options.
-
In the Multi-Factor Authentication (MFA) section, click Configure.
-
In the Secure your account window, scan the displayed QR code with your mobile device. The authenticator app displays a verification code for 30 seconds.
-
Enter the code in the Code field.
-
Click Continue.
MFA is configured successfully.
Managing Multi-Factor Authentication for Check Point Portal Users
This video shows you how to manage Multi-Factor Authentication for Check Point Portal users.
Watch the Video
A Check Point Portal Primary Administrator, Admin, or User Admin can view and reset a user's MFA configuration.
In the Check Point Portal, click
> Users.
The 2FA configured column of the table shows one of these Multi-Factor Authentication configurations for each user:
|
Icon |
MFA Configuration |
|---|---|
|
No icon |
The user does not have MFA configured. |
|
|
The user has MFA configured with an authenticator app. |
|
|
The user has MFA configured with SMS. |
|
|
The user has MFA configured with an authenticator app and with SMS. |
The MFA table row shows you the MFA authentication method(s) that the user configured for themselves in Profile Settings. This table row is not related to the MFA enforcement policy for the account.
Reset a user's phone number in these scenarios:
-
The user gets a new phone with a new number.
-
The user's phone is lost or stolen.
-
The user has a problem using MFA with SMS.
To reset the user phone number:
-
In the Check Point Portal, click
> Users. -
Click the table row with the name of the user.
-
Click Edit.
The Edit User window opens.
-
In the Phone number field, enter a phone number for the user.
-
Click Save.
Reset an authentication app for a user when the user gets a new phone (with the same phone number) or has a problem with the app.
After the reset, if MFA is required for account login, Check Point sends an SMS with an authentication code to the user's verified phone number. Then, the user can log in to the Check Point Portal and create a new authenticator app configuration (see Configure an authentication app for MFA).
To reset an MFA application:
-
In the Check Point Portal, click
> Users.The 2FA configured column of the table shows one of these Multi-Factor Authentication configurations for each user:
Icon
MFA Configuration
No icon
The user does not have MFA configured.
By appThe user has MFA configured with an authenticator app.
By phoneThe user has MFA configured with SMS.
App and phoneThe user has MFA configured with an authenticator app and with SMS.
-
Select a user from the table and click Reset MFA.
-
To see updated user information, click Refresh.
Enforcing MFA Policy for All Users
A Primary Administrator must set up an MFA policy for all users who log in to the Check Point Portal account with their username and password.
|
|
Notes:
|
This video shows you how to enforce MFA for all users of an Check Point Portal account.
Watch the Video
MFA enforcement settings on the Identity & Access page apply to all users of this Check Point Portal account. Only a Primary Administrator can change these settings.
-
In the Check Point Portal, click
> Identity & Access. -
In the Multi-Factor Authentication (MFA) to the Check Point Portal section, select when to enforce MFA:
-
Enforce MFA for all logins, including SSO - Users must use MFA to log in with username and password and for login with SSO through an Identity Provider.
-
Enforce MFA for login with username and password - This option is selected by default.
A confirmation window opens.
-
-
In the confirmation window, click Enforce.
A Primary Administrator can allow Check Point Portal users to bypass the MFA verification for 14 days after they successfully sign in to the Check Point Portal with a trusted device.
-
In the Check Point Portal, click
> Identity & Access. -
In the Multi-Factor Authentication (MFA) to the Check Point Portal section, select Allow trusted devices to skip MFA for 14 days.
When users enter their verification code on their login to the Check Point Portal, they can select the option Remember this device for 14 days.
Enforcing MFA Policy for Child Accounts using API
Because MFA is mandatory for all accounts that use a username and password to log in, primary administrators must enforce the MFA policy for all child accounts. These are Customer accounts managed by MSSPs or by a Customer Parent in a large enterprise.
Primary administrators that manage multiple accounts may need access to the child accounts that use API automation. To get access, the primary administrator needs an Account API key to create new API keys for child accounts. For more information, see API Keys.