Skip to content

Enabling Multi Factor Authentication (MFA) in Oracle Cloud

MFA is very critical for Cloud Security. Below are one-time setup steps to make MFA enabled for all users in OCI. After following these steps, all users will be prompted to set up MFA on their next login. After setting up MFA, the user will be required to provide an MFA code in addition to their password when logging in to Oracle Cloud.

For enabling MFA FOR IDCS federated users,

Go to IDCS Admin console

Select MFA under Security

Choose whatever factor you want to enable for users and click save:

Multi-Factor Authentication (MFA) Settings 
Select the factors that you want to enable: O 
a Secunty Questions 
Mobile App Passcode 
Mobile App Notification 
Text Message (SMS) 
Emai 
Bypass Code 
Trusted Device(s) 
Enable Trusted Device(s) 
Number of day(s) a device can be trusted 
15 
Maximum number of trusted device(s) 
Configure 
Configure 
Configure 
Configure

 

 

 

And then changed the sign-on policies

O 
Identity Providers 
IDP Policies 
Sign-On Policies 
Network Perimeters 
App Gateways 
Account Recovery 
MFA

 

Either edit the default sign-on policy or create a custom policy

Select All Add 
X Remove 
e,) Activate 
Ø Deactivate 
Default Sign-On Policy 
Page 1 of 1 
(1 of 1 items) 
Default Sign on Policy for Tenant 
o 
Deactivate 
Edit

Click on sign-on rules and click edit

Default Sign-On Policy 
Details Sign-On Rules Apps 
Select All Add X Remove 
Default Sign-On Rule 
Edit

Select either “any factor” or “specific factor” as per need

Actions 
Access is Allowed 
D Prompt for reauthentication 
factor 
o 
@ Any Factor 
C) Specific Factor 
Frequency 
@ Once per Session Or Trusted device O 
C) Every time 
O Once every 
Enrollment Required 
o 
O 
Save

 

 

The below screen will prompt now for our tenancy for ALL users trying to access to do 2-factor authentication:

 

 

Any method can be chosen by the user since we enabled all the factors in this example:

We enabled the mobile app so the cell phone was enrolled.

Next time when user will log in, the user will get the below screen:

Only after successful verification on the cell phone, the Console will appear.

ORACLE Cloud 
Quick Actions 
COMPUTE 
Create a VM instance 
2-6 mins 
OBJECT STORAGE 
Store data 
Search for resources, services and documentation 
AUTONOMOUS TRANSACTION PROCESSING 
Create an ATP database 
3-5 
RESOURCE MANAGER 
Create a stack

 

Please note that the MFA setup process might be slightly different depending on the Oracle Cloud version or edition you are using, and the specific feature set available to you, please refer to the Oracle Cloud documentation for more detailed steps on how to enable MFA for your specific case.

Brijesh Gogia
Leave a Reply