- play_arrow Overview
- play_arrow Juniper Advanced Threat Prevention Cloud Overview
- play_arrow Juniper Advanced Threat Cloud Prevention Setup
-
- play_arrow Juniper ATP Cloud Web Portal
- play_arrow Juniper ATP Cloud Web Portal Overview
-
- play_arrow Enroll SRX Series Firewalls in Juniper ATP Cloud Web Portal
- play_arrow Enroll and Manage SRX Series Firewalls
-
- play_arrow Monitor Juniper ATP Cloud Features
- play_arrow Reports
- play_arrow Hosts
- play_arrow Identify Infected Hosts
- play_arrow Threat Sources
- play_arrow Identify Hosts Communicating with Command and Control Servers
- play_arrow IoT Device Discovery and Classification
- play_arrow Reverse Shell
- play_arrow Files
- play_arrow E-mails
- play_arrow Statistics
- play_arrow DNS
- play_arrow Encrypted Traffic Insights
-
- play_arrow Configure Juniper ATP Cloud Features
- play_arrow Allowlists and Blocklists
- play_arrow Email Scanning: Juniper ATP Cloud
- play_arrow File Inspection Profiles
- play_arrow Adaptive Threat Profiling
- play_arrow Feeds Configuration
- play_arrow Infected Hosts
- play_arrow Threat Intelligence Sharing
- play_arrow Misc Configurations
-
- play_arrow More Documentation
- play_arrow ATP Cloud Tech Library Page Links
-
Configure Multi-Factor Authentication for Administrators
Enable Multi-Factor Authentication
When you enable multi-factor authentication for a realm, it is turned on for all administrators in at realm. You must be a System Administrator to enable multi-factor authentication.
To enable and configure multi-factor authentication settings, navigate to Administration > Multifactor Authentication.
Verification Codes for Multi-Factor Authentication: SMS
When SMS is set as the authentication method, the first time an administrator attempts to log in to the Juniper ATP Cloud Web UI (enters a username and password), a Verify Identity screen appears. Administrators must enter the following information in the Verify Identity screen:
Select the country where the mobile number was issued.
Enter their mobile phone number (numbers only, no dashes or other characters)
Click the Send Code button. A verification code is sent to the mobile device.
Once the code is received by text or email, enter the 8 digit code in the Verification Code field.
Click Verify.
Lockout Conditions:If an administrator does not receive the code, she can click the Send Code button again. Note the following security precautions in place for resending code requests: ATP Cloud will wait 60 seconds after sending a code before it will send another code once a request is made. Once a user has requested a verification code 4 times without logging in to ATP Cloud, she is permanently locked out. In this case, the user must contact an administrator to remove the lock.
Verification Codes for Multi-Factor Authentication: Email
When Email is set as the authentication method, the first time an administrator attempts to log in to the Juniper ATP Cloud Web UI (by entering a username and password), a Verify Identity screen appears. Users must enter the following information:
Enter the 8 digit verification code contained in the email.
Click Verify.
If a user does not receive the code, she should check her spam folder. If it’s not there, she can click the Resend Code button. Note the following security precautions about resending code requests. ATP Cloud will wait 60 seconds after sending a code before it will send another code once a request is made. Once a user has requested a verification code 4 times without logging in to ATP Cloud, she is locked out for 1 hour, meaning a new code cannot be requested for that amount of time.
When Email is the MFA method, the one hour lockout cannot be cleared. The user must wait the full hour before requesting another verification code.
Unlock a User
An SMS lockout can be removed by a system administrator who is logged into Juniper ATP Cloud.
To remove the lockout,
- Navigate to Administration > Users and locate the locked out user.
- Select the check box to edit the user.
- On the User Edit screen is MFA Method and Mobile Number. Click the link to Reset mobile number. This removes the lock, allowing the user to step through the Verification Identity screen again, and the code request counter is reset to zero.