Appearance
Multi-Factor Authentication
WebWorkstationMobileMulti-factor authentication, or MFA, adds an extra verification step after a user's primary sign-in method. The current ZynoSuite user interface does not include a general self-service MFA setup page for all users.
ZynoSuite currently relies on these user-visible security paths:
| Method | Where It Applies |
|---|---|
| Provider MFA | Microsoft Entra or Google Workspace SSO, configured in your identity provider |
| Fingerprint login | ZynoWorkstation installations with a supported fingerprint reader |
| ZynoRMM hardware authenticators | ZynoRMM secure operations, where that module is enabled |
Provider MFA
If your organization uses SSO, configure MFA rules in Microsoft Entra or Google Workspace. ZynoSuite sends the user to the provider during sign-in, and the provider handles its own MFA prompts.
This is the recommended MFA path for organizations already using a central identity provider.
Fingerprint Login
Fingerprint login is available only on ZynoWorkstation when the workstation has a supported fingerprint reader and the user has permission to manage fingerprints.
Fingerprint login is not the same as a general web MFA prompt. It is a Workstation sign-in method for shared or hardware-connected workstation environments.
See Fingerprint Login.
Passkeys
The authentication platform recognizes passkey/WebAuthn as an MFA mechanism, but the main ZynoSuite user interface does not currently expose a general passkey enrollment screen for standard web sign-in.
Where passkeys or hardware authenticators appear today, they are tied to specific secure workflows such as ZynoRMM.
See Passkeys.
What to Tell Users
For most organizations:
- Web users should follow the MFA process enforced by Microsoft Entra or Google Workspace.
- Workstation users can use fingerprint login when their workstation supports it.
- Users should not expect a general "set up MFA" screen in ZynoSuite unless your organization has enabled a workflow that exposes one.