Last modified by Alex Cotiuga on 2026/07/13 06:59

From version 1.16
edited by Alex Cotiuga
on 2026/05/22 03:49
Change comment: There is no comment for this version
To version 30.5
edited by Alex Cotiuga
on 2026/07/13 06:57
Change comment: There is no comment for this version

Summary

Details

Page properties
Title
... ... @@ -1,1 +1,1 @@
1 -xwiki-two-factor-authentication
1 +XWiki Two-Factor Authentication
Default language
... ... @@ -1,1 +1,0 @@
1 -en
Hidden
... ... @@ -1,1 +1,1 @@
1 -false
1 +true
Content
... ... @@ -1,31 +1,500 @@
1 -<article class="product-card">
2 - <div class="product-card-icon">
3 - <i class="fa fa-lock" aria-hidden="true"></i>
4 - </div>
1 +{{velocity}}
2 +#set ($discard = $xwiki.ssx.use('PublicWebSite.WebHome'))
5 5  
6 - <div class="product-card-body">
7 - <div class="hero-kicker product-card-kicker">
4 +#set ($mainCapabilityItems = [{
5 + 'title': 'Second verification step',
6 + 'icon': 'key',
7 + 'content': 'Add an additional verification screen after the normal XWiki username and password login.'
8 +},{
9 + 'title': 'Authenticator app codes',
10 + 'icon': 'mobile',
11 + 'content': 'Let users verify access with time-based TOTP codes generated by authenticator applications.'
12 +},{
13 + 'title': 'Recovery and trusted devices',
14 + 'icon': 'shield',
15 + 'content': 'Provide backup access with recovery codes and reduce repeated prompts on trusted browsers.'
16 +}])
17 +
18 +#set ($adminExperienceItems = [{
19 + 'title': 'Rollout policy',
20 + 'icon': 'cog',
21 + 'content': 'Make additional verification optional at first or required for all users from the XWiki Administration section.'
22 +},{
23 + 'title': 'Configuration options',
24 + 'icon': 'sliders',
25 + 'content': 'Set the authenticator issuer name, recovery-code count and trusted-device duration.'
26 +},{
27 + 'title': 'Administration overview',
28 + 'icon': 'table',
29 + 'content': 'Review adoption with summary indicators and a filterable Live Data table.'
30 +}])
31 +
32 +#set ($userExperienceItems = [{
33 + 'title': 'Self-service setup',
34 + 'icon': 'qrcode',
35 + 'content': 'Users configure the second verification step from their profile by scanning a QR code or entering the setup key manually.'
36 +},{
37 + 'title': 'Login verification',
38 + 'icon': 'sign-in',
39 + 'content': 'After the normal login, users enter the verification code generated by their authenticator app.'
40 +},{
41 + 'title': 'Trusted browser option',
42 + 'icon': 'desktop',
43 + 'content': 'Users can trust the current browser for the configured duration after successful verification.'
44 +}])
45 +
46 +#set ($selfServiceItems = [{
47 + 'title': 'Recovery codes',
48 + 'icon': 'life-ring',
49 + 'content': 'Recovery codes provide backup access when a user loses access to the authenticator application.'
50 +},{
51 + 'title': 'Trusted devices',
52 + 'icon': 'desktop',
53 + 'content': 'Trusted devices can be reviewed and removed from the user profile.'
54 +},{
55 + 'title': 'Profile management',
56 + 'icon': 'user',
57 + 'content': 'Users can review status, generate recovery codes, manage trusted devices and reset their setup.'
58 +}])
59 +
60 +#set ($adminSupportItems = [{
61 + 'title': 'User status',
62 + 'icon': 'user',
63 + 'content': 'Administrators can open a user profile and check the verification status for that account.'
64 +},{
65 + 'title': 'Setup reset',
66 + 'icon': 'refresh',
67 + 'content': 'Administrators can reset the setup when a user needs to restart the configuration process.'
68 +},{
69 + 'title': 'Controlled recovery',
70 + 'icon': 'unlock-alt',
71 + 'content': 'Resetting the setup removes the authenticator configuration, recovery codes and trusted devices for that user.'
72 +}])
73 +
74 +#set ($rolloutItems = [{
75 + 'title': 'Start with a pilot group',
76 + 'content': 'Test the extension with administrators or a small user group before enabling it widely.'
77 +},{
78 + 'title': 'Define the rollout policy',
79 + 'content': 'Decide whether additional verification should be optional at first or required for all users.'
80 +},{
81 + 'title': 'Configure recovery options',
82 + 'content': 'Choose the number of recovery codes and whether trusted devices should be allowed.'
83 +},{
84 + 'title': 'Inform users',
85 + 'content': 'Explain how users configure the authenticator app, save recovery codes and manage trusted devices.'
86 +},{
87 + 'title': 'Monitor adoption',
88 + 'content': 'Use the administration overview to identify users who still need to configure protection.'
89 +}])
90 +
91 +{{html clean="false"}}
92 +
93 +<section class="hero hero-centered" aria-labelledby="product-title">
94 + <div class="container hero-inner">
95 + <div class="hero-kicker">
8 8   <i class="fa fa-lock" aria-hidden="true"></i>
9 - Security extension
97 + XWiki 2FA with MFA rollout support
10 10   </div>
11 11  
12 - <h3>XWiki Two-Factor Authentication</h3>
100 + <h1 id="product-title">XWiki Two-Factor Authentication</h1>
13 13  
14 - <p>
15 - Add XWiki 2FA/MFA protection to the standard login flow with authenticator app codes,
16 - email verification codes, optional combined verification, and trusted-device remembering.
102 + <p class="lead">
103 + Protect XWiki logins with authenticator app verification, recovery codes,
104 + trusted devices and administration controls for a safer rollout.
17 17   </p>
18 18  
19 - <ul class="product-highlights">
20 - <li>Works with the standard XWiki authentication flow</li>
21 - <li>Supports app codes, email codes, or both</li>
22 - <li>Helps protect administrator and remote-access accounts</li>
23 - </ul>
107 + <div class="product-card-kicker">
108 + <i class="fa fa-tag" aria-hidden="true"></i>
109 + Extension from €95/year · Basic setup from €150
110 + </div>
24 24  
25 - <p class="card-link">
26 - <a class="btn btn-secondary" href="$xwiki.getURL('products.xwiki-two-factor-authentication')">
27 - View extension
28 - </a>
112 + <div class="hero-actions">
113 + <a class="btn btn-primary" href="$xwiki.getURL('contact.WebHome')">Ask about this extension</a>
114 + <a class="btn btn-secondary" href="$xwiki.getURL('pricing.WebHome')#common-packages">View MFA setup price</a>
115 + </div>
116 + </div>
117 +</section>
118 +
119 +<section aria-labelledby="overview-title">
120 + <div class="container">
121 + <div class="product-layout">
122 + <article class="product-summary-card">
123 + <h2 id="overview-title">Two-factor authentication built into XWiki</h2>
124 +
125 + <p>
126 + XWiki Two-Factor Authentication adds an additional verification step to the standard
127 + XWiki login flow. Users continue to sign in with their normal username and password,
128 + then confirm access with a time-based code from an authenticator application.
129 + </p>
130 +
131 + <p>
132 + The application has evolved beyond a simple login-code screen. It supports global
133 + enforcement, recovery codes, trusted devices, user self-service, administrator
134 + reset actions and an overview for monitoring adoption.
135 + </p>
136 + </article>
137 +
138 + <aside class="product-info-card" aria-labelledby="quick-facts-title">
139 + <h3 id="quick-facts-title">Quick facts</h3>
140 + <ul>
141 + <li>Works with the standard XWiki login flow</li>
142 + <li>Supports TOTP authenticator applications</li>
143 + <li>Can require additional verification for all users</li>
144 + <li>Includes one-time recovery codes</li>
145 + <li>Can remember trusted browsers or devices</li>
146 + <li>Includes user self-service controls</li>
147 + <li>Includes an administration overview</li>
148 + </ul>
149 + </aside>
150 + </div>
151 + </div>
152 +</section>
153 +
154 +<section aria-labelledby="capabilities-title">
155 + <div class="container">
156 + <h2 id="capabilities-title">Main capabilities</h2>
157 +
158 + <p class="section-intro">
159 + A focused set of authentication protection features for stronger XWiki account security
160 + without replacing the familiar login experience.
29 29   </p>
162 +
163 + <div class="product-feature-grid">
164 + #foreach ($entry in $mainCapabilityItems)
165 + <article class="product-feature">
166 + <div class="card-heading">
167 + <div class="feature-icon">
168 + <i class="fa fa-$entry.icon" aria-hidden="true"></i>
169 + </div>
170 + <h3>$entry.title</h3>
171 + </div>
172 +
173 + <p>$entry.content</p>
174 + </article>
175 + #end
176 + </div>
30 30   </div>
31 -</article>
178 +</section>
179 +
180 +<section class="product-section-muted" aria-labelledby="security-title">
181 + <div class="container">
182 + <div class="product-layout">
183 + <article class="product-summary-card">
184 + <h2 id="security-title">Useful for XWiki security and access protection</h2>
185 +
186 + <p>
187 + Many organizations use XWiki to store internal documentation, procedures, operational
188 + knowledge and business-critical information. Adding an additional authentication factor helps
189 + reduce the risk of account compromise when a password is exposed or reused.
190 + </p>
191 +
192 + <p>
193 + The extension is especially useful for protecting administrator accounts, remote users,
194 + private knowledge bases and customer or partner portals.
195 + </p>
196 + </article>
197 +
198 + <aside class="product-info-card" aria-labelledby="use-cases-title">
199 + <h3 id="use-cases-title">Typical use cases</h3>
200 + <ul>
201 + <li>Administrator account protection</li>
202 + <li>Internal knowledge base security</li>
203 + <li>Private documentation platforms</li>
204 + <li>Remote user access protection</li>
205 + <li>Customer or partner portals</li>
206 + <li>Security review, MFA rollout and compliance readiness</li>
207 + </ul>
208 + </aside>
209 + </div>
210 + </div>
211 +</section>
212 +
213 +<section aria-labelledby="admin-experience-title">
214 + <div class="container">
215 + <h2 id="admin-experience-title">Administrator configuration and monitoring</h2>
216 +
217 + <p class="section-intro">
218 + Administrators can configure the policy, define recovery options and monitor adoption
219 + from the XWiki Administration section.
220 + </p>
221 +
222 + <div class="product-feature-grid">
223 + #foreach ($entry in $adminExperienceItems)
224 + <article class="product-feature">
225 + <div class="card-heading">
226 + <div class="feature-icon">
227 + <i class="fa fa-$entry.icon" aria-hidden="true"></i>
228 + </div>
229 + <h3>$entry.title</h3>
230 + </div>
231 +
232 + <p>$entry.content</p>
233 + </article>
234 + #end
235 + </div>
236 +
237 +{{/html}}
238 +
239 +{{gallery}}
240 +[[image:mfa-admin-configuration.png]]
241 +[[image:mfa-admin-overview.png]]
242 +[[image:mfa-admin-full.png]]
243 +{{/gallery}}
244 +
245 +{{html clean="false"}}
246 +
247 + <p class="product-gallery-caption">
248 + Administration screens for configuring the policy and reviewing adoption across users.
249 + </p>
250 + </div>
251 +</section>
252 +
253 +<section class="product-section-muted" aria-labelledby="user-experience-title">
254 + <div class="container">
255 + <h2 id="user-experience-title">User setup and login verification</h2>
256 +
257 + <p class="section-intro">
258 + Users can configure the authenticator app from their profile or during the enforced setup flow,
259 + then verify future logins with a generated code.
260 + </p>
261 +
262 + <div class="product-feature-grid">
263 + #foreach ($entry in $userExperienceItems)
264 + <article class="product-feature">
265 + <div class="card-heading">
266 + <div class="feature-icon">
267 + <i class="fa fa-$entry.icon" aria-hidden="true"></i>
268 + </div>
269 + <h3>$entry.title</h3>
270 + </div>
271 +
272 + <p>$entry.content</p>
273 + </article>
274 + #end
275 + </div>
276 +
277 +{{/html}}
278 +
279 +{{gallery}}
280 +[[image:mfa-user-setup-qr.png]]
281 +[[image:mfa-login-verification-setup.png]]
282 +[[image:mfa-login-verification-code.png]]
283 +{{/gallery}}
284 +
285 +{{html clean="false"}}
286 +
287 + <p class="product-gallery-caption">
288 + User setup, enforced configuration and login verification screens.
289 + </p>
290 + </div>
291 +</section>
292 +
293 +<section aria-labelledby="self-service-title">
294 + <div class="container">
295 + <h2 id="self-service-title">Recovery codes and trusted devices</h2>
296 +
297 + <p class="section-intro">
298 + Recovery codes and trusted devices help balance stronger access protection with a smoother user experience.
299 + </p>
300 +
301 + <div class="product-feature-grid">
302 + #foreach ($entry in $selfServiceItems)
303 + <article class="product-feature">
304 + <div class="card-heading">
305 + <div class="feature-icon">
306 + <i class="fa fa-$entry.icon" aria-hidden="true"></i>
307 + </div>
308 + <h3>$entry.title</h3>
309 + </div>
310 +
311 + <p>$entry.content</p>
312 + </article>
313 + #end
314 + </div>
315 +
316 +{{/html}}
317 +
318 +{{gallery}}
319 +[[image:mfa-user-profile-overview.png]]
320 +[[image:mfa-recovery-codes-not-generated.png]]
321 +[[image:mfa-recovery-codes-generated.png]]
322 +[[image:mfa-trusted-devices.png]]
323 +[[image:mfa-user-profile-full.png]]
324 +{{/gallery}}
325 +
326 +{{html clean="false"}}
327 +
328 + <p class="product-gallery-caption">
329 + User profile screens for recovery codes, trusted devices and self-service management.
330 + </p>
331 + </div>
332 +</section>
333 +
334 +<section class="product-section-muted" aria-labelledby="admin-support-title">
335 + <div class="container">
336 + <h2 id="admin-support-title">Administrator support and user recovery</h2>
337 +
338 + <p class="section-intro">
339 + Administrators can help users recover from lost devices or restart setup when needed.
340 + </p>
341 +
342 + <div class="product-feature-grid">
343 + #foreach ($entry in $adminSupportItems)
344 + <article class="product-feature">
345 + <div class="card-heading">
346 + <div class="feature-icon">
347 + <i class="fa fa-$entry.icon" aria-hidden="true"></i>
348 + </div>
349 + <h3>$entry.title</h3>
350 + </div>
351 +
352 + <p>$entry.content</p>
353 + </article>
354 + #end
355 + </div>
356 +
357 +{{/html}}
358 +
359 +{{gallery}}
360 +[[image:mfa-admin-user-management.png]]
361 +{{/gallery}}
362 +
363 +{{html clean="false"}}
364 +
365 + <p class="product-gallery-caption">
366 + Administrator view for checking and resetting a user setup.
367 + </p>
368 + </div>
369 +</section>
370 +
371 +<section aria-labelledby="faq-title">
372 + <div class="container">
373 + <h2 id="faq-title">Frequently asked questions</h2>
374 +
375 + <p class="section-intro">
376 + Common questions about how the extension works, how users configure it and how administrators can manage rollout and recovery.
377 + </p>
378 +
379 + <div class="resource-content">
380 + <details class="resource-faq-item">
381 + <summary>Does this extension replace the standard XWiki login?</summary>
382 + <p>
383 + No. Users still sign in with their normal XWiki username and password. The extension adds
384 + an additional verification step after the standard login check.
385 + </p>
386 + </details>
387 +
388 + <details class="resource-faq-item">
389 + <summary>Which verification method is used?</summary>
390 + <p>
391 + Users verify access with time-based codes generated by an authenticator application.
392 + The setup page provides a QR code and a manual setup key.
393 + </p>
394 + </details>
395 +
396 + <details class="resource-faq-item">
397 + <summary>Can the second verification step be required for all users?</summary>
398 + <p>
399 + Yes. Administrators can make the verification step optional or required for all users
400 + from the XWiki Administration section.
401 + </p>
402 + </details>
403 +
404 + <details class="resource-faq-item">
405 + <summary>What happens if a user loses access to the authenticator app?</summary>
406 + <p>
407 + Recovery codes can provide backup access when enabled. Administrators can also reset
408 + the user setup so the configuration process can be restarted.
409 + </p>
410 + </details>
411 +
412 + <details class="resource-faq-item">
413 + <summary>Can trusted browsers or devices be disabled?</summary>
414 + <p>
415 + Yes. Administrators can configure how long trusted devices remain valid. Setting the
416 + trusted-device duration to 0 disables this option.
417 + </p>
418 + </details>
419 +
420 + <details class="resource-faq-item">
421 + <summary>Is this only a basic 2FA login-code screen?</summary>
422 + <p>
423 + No. The main login mechanism is two-factor authentication, but the application also includes
424 + features needed for a safer organization-wide rollout: enforcement policy, recovery codes,
425 + trusted devices, user self-service, administrator monitoring and administrator reset actions.
426 + </p>
427 + </details>
428 +
429 + <details class="resource-faq-item">
430 + <summary>Is this enough for compliance on its own?</summary>
431 + <p>
432 + No. This extension provides an important access-protection control, but it should be part
433 + of a broader security and compliance approach that includes permissions, upgrades,
434 + infrastructure, monitoring and operational procedures.
435 + </p>
436 + </details>
437 + </div>
438 + </div>
439 +</section>
440 +
441 +<section class="product-section-muted" aria-labelledby="rollout-title">
442 + <div class="container">
443 + <div class="product-layout">
444 + <article class="product-summary-card">
445 + <h2 id="rollout-title">Rollout recommendations</h2>
446 +
447 + <p>
448 + For a smooth rollout, start with a small administrator or pilot group before requiring
449 + the additional verification step for everyone. This helps validate the configuration,
450 + prepare user communication and reduce support issues.
451 + </p>
452 +
453 + <ol class="process-list">
454 + #foreach ($entry in $rolloutItems)
455 + <li>
456 + <strong>$entry.title</strong>
457 + $entry.content
458 + </li>
459 + #end
460 + </ol>
461 + </article>
462 +
463 + <aside class="product-info-card" aria-labelledby="planning-title">
464 + <h3 id="planning-title">Useful information before installation</h3>
465 +
466 + <p class="product-card-note">
467 + These details help evaluate compatibility, rollout scope and configuration options.
468 + </p>
469 +
470 + <ul>
471 + <li>XWiki version</li>
472 + <li>Single wiki or wiki farm with subwikis</li>
473 + <li>Current authentication setup</li>
474 + <li>Optional or required rollout policy</li>
475 + <li>Trusted-device policy</li>
476 + <li>Recovery-code policy</li>
477 + <li>Rollout communication needs</li>
478 + </ul>
479 + </aside>
480 + </div>
481 + </div>
482 +</section>
483 +
484 +<section class="cta-section" aria-labelledby="cta-title">
485 + <div class="container">
486 + <div class="cta-panel">
487 + <h2 id="cta-title">Interested in using this extension?</h2>
488 +
489 + <p>
490 + Send a short message with your XWiki version, current authentication setup and rollout goal.
491 + </p>
492 +
493 + <a class="btn btn-primary" href="$xwiki.getURL('contact.WebHome')">Contact Agnease</a>
494 + <a class="btn btn-secondary" href="$xwiki.getURL('pricing.WebHome')#common-packages">View MFA setup price</a>
495 + </div>
496 + </div>
497 +</section>
498 +
499 +{{/html}}
500 +{{/velocity}}
2fa-authenticator.png
Author
... ... @@ -1,0 +1,1 @@
1 +XWiki.Admin
Size
... ... @@ -1,0 +1,1 @@
1 +1.1 MB
Content
mfa-admin-configuration.png
Author
... ... @@ -1,0 +1,1 @@
1 +XWiki.Admin
Size
... ... @@ -1,0 +1,1 @@
1 +125.3 KB
Content
mfa-admin-full.png
Author
... ... @@ -1,0 +1,1 @@
1 +XWiki.Admin
Size
... ... @@ -1,0 +1,1 @@
1 +184.3 KB
Content
mfa-admin-overview.png
Author
... ... @@ -1,0 +1,1 @@
1 +XWiki.Admin
Size
... ... @@ -1,0 +1,1 @@
1 +64.7 KB
Content
mfa-admin-user-management.png
Author
... ... @@ -1,0 +1,1 @@
1 +XWiki.Admin
Size
... ... @@ -1,0 +1,1 @@
1 +90.8 KB
Content
mfa-login-verification-code.png
Author
... ... @@ -1,0 +1,1 @@
1 +XWiki.Admin
Size
... ... @@ -1,0 +1,1 @@
1 +23.6 KB
Content
mfa-login-verification-setup.png
Author
... ... @@ -1,0 +1,1 @@
1 +XWiki.Admin
Size
... ... @@ -1,0 +1,1 @@
1 +115.9 KB
Content
mfa-recovery-codes-generated.png
Author
... ... @@ -1,0 +1,1 @@
1 +XWiki.Admin
Size
... ... @@ -1,0 +1,1 @@
1 +38.5 KB
Content
mfa-recovery-codes-not-generated.png
Author
... ... @@ -1,0 +1,1 @@
1 +XWiki.Admin
Size
... ... @@ -1,0 +1,1 @@
1 +27.0 KB
Content
mfa-trusted-devices.png
Author
... ... @@ -1,0 +1,1 @@
1 +XWiki.Admin
Size
... ... @@ -1,0 +1,1 @@
1 +59.1 KB
Content
mfa-user-profile-full.png
Author
... ... @@ -1,0 +1,1 @@
1 +XWiki.Admin
Size
... ... @@ -1,0 +1,1 @@
1 +197.5 KB
Content
mfa-user-profile-overview.png
Author
... ... @@ -1,0 +1,1 @@
1 +XWiki.Admin
Size
... ... @@ -1,0 +1,1 @@
1 +193.4 KB
Content
mfa-user-setup-qr.png
Author
... ... @@ -1,0 +1,1 @@
1 +XWiki.Admin
Size
... ... @@ -1,0 +1,1 @@
1 +176.6 KB
Content
Agnease.Code.SEODetailsClass[0]
metaDescription
... ... @@ -1,0 +1,1 @@
1 +Agnease Two-Factor Authentication for XWiki adds a second login verification step with authenticator app codes, email codes, combined verification and trusted-device remembering.
metaTitle
... ... @@ -1,0 +1,1 @@
1 +XWiki Two-Factor Authentication with 2FA and MFA Support | Agnease