Last modified by Alex Cotiuga on 2026/07/13 06:59

From version 1.16
edited by Alex Cotiuga
on 2026/05/22 03:49
Change comment: There is no comment for this version
To version 30.6
edited by Alex Cotiuga
on 2026/07/13 06:59
Change comment: There is no comment for this version

Summary

Details

Page properties
Title
... ... @@ -1,1 +1,1 @@
1 -xwiki-two-factor-authentication
1 +XWiki Two-Factor Authentication
Default language
... ... @@ -1,1 +1,0 @@
1 -en
Hidden
... ... @@ -1,1 +1,1 @@
1 -false
1 +true
Content
... ... @@ -1,31 +1,501 @@
1 -<article class="product-card">
2 - <div class="product-card-icon">
3 - <i class="fa fa-lock" aria-hidden="true"></i>
4 - </div>
1 +{{velocity}}
2 +#set ($discard = $xwiki.ssx.use('PublicWebSite.WebHome'))
5 5  
6 - <div class="product-card-body">
7 - <div class="hero-kicker product-card-kicker">
4 +#set ($mainCapabilityItems = [{
5 + 'title': 'Second verification step',
6 + 'icon': 'key',
7 + 'content': 'Add an additional verification screen after the normal XWiki username and password login.'
8 +},{
9 + 'title': 'Authenticator app codes',
10 + 'icon': 'mobile',
11 + 'content': 'Let users verify access with time-based TOTP codes generated by authenticator applications.'
12 +},{
13 + 'title': 'Recovery and trusted devices',
14 + 'icon': 'shield',
15 + 'content': 'Provide backup access with recovery codes and reduce repeated prompts on trusted browsers.'
16 +}])
17 +
18 +#set ($adminExperienceItems = [{
19 + 'title': 'Rollout policy',
20 + 'icon': 'cog',
21 + 'content': 'Make additional verification optional at first or required for all users from the XWiki Administration section.'
22 +},{
23 + 'title': 'Configuration options',
24 + 'icon': 'sliders',
25 + 'content': 'Set the authenticator issuer name, recovery-code count and trusted-device duration.'
26 +},{
27 + 'title': 'Administration overview',
28 + 'icon': 'table',
29 + 'content': 'Review adoption with summary indicators and a filterable Live Data table.'
30 +}])
31 +
32 +#set ($userExperienceItems = [{
33 + 'title': 'Self-service setup',
34 + 'icon': 'qrcode',
35 + 'content': 'Users configure the second verification step from their profile by scanning a QR code or entering the setup key manually.'
36 +},{
37 + 'title': 'Login verification',
38 + 'icon': 'sign-in',
39 + 'content': 'After the normal login, users enter the verification code generated by their authenticator app.'
40 +},{
41 + 'title': 'Trusted browser option',
42 + 'icon': 'desktop',
43 + 'content': 'Users can trust the current browser for the configured duration after successful verification.'
44 +}])
45 +
46 +#set ($selfServiceItems = [{
47 + 'title': 'Recovery codes',
48 + 'icon': 'life-ring',
49 + 'content': 'Recovery codes provide backup access when a user loses access to the authenticator application.'
50 +},{
51 + 'title': 'Trusted devices',
52 + 'icon': 'desktop',
53 + 'content': 'Trusted devices can be reviewed and removed from the user profile.'
54 +},{
55 + 'title': 'Profile management',
56 + 'icon': 'user',
57 + 'content': 'Users can review status, generate recovery codes, manage trusted devices and reset their setup.'
58 +}])
59 +
60 +#set ($adminSupportItems = [{
61 + 'title': 'User status',
62 + 'icon': 'user',
63 + 'content': 'Administrators can open a user profile and check the verification status for that account.'
64 +},{
65 + 'title': 'Setup reset',
66 + 'icon': 'refresh',
67 + 'content': 'Administrators can reset the setup when a user needs to restart the configuration process.'
68 +},{
69 + 'title': 'Controlled recovery',
70 + 'icon': 'unlock-alt',
71 + 'content': 'Resetting the setup removes the authenticator configuration, recovery codes and trusted devices for that user.'
72 +}])
73 +
74 +#set ($rolloutItems = [{
75 + 'title': 'Start with a pilot group',
76 + 'content': 'Test the extension with administrators or a small user group before enabling it widely.'
77 +},{
78 + 'title': 'Define the rollout policy',
79 + 'content': 'Decide whether additional verification should be optional at first or required for all users.'
80 +},{
81 + 'title': 'Configure recovery options',
82 + 'content': 'Choose the number of recovery codes and whether trusted devices should be allowed.'
83 +},{
84 + 'title': 'Inform users',
85 + 'content': 'Explain how users configure the authenticator app, save recovery codes and manage trusted devices.'
86 +},{
87 + 'title': 'Monitor adoption',
88 + 'content': 'Use the administration overview to identify users who still need to configure protection.'
89 +}])
90 +
91 +{{html clean="false"}}
92 +
93 +<section class="hero hero-centered" aria-labelledby="product-title">
94 + <div class="container hero-inner">
95 + <div class="hero-kicker">
8 8   <i class="fa fa-lock" aria-hidden="true"></i>
9 - Security extension
97 + XWiki 2FA with MFA rollout support
10 10   </div>
11 11  
12 - <h3>XWiki Two-Factor Authentication</h3>
100 + <h1 id="product-title">XWiki Two-Factor Authentication</h1>
13 13  
14 - <p>
15 - Add XWiki 2FA/MFA protection to the standard login flow with authenticator app codes,
16 - email verification codes, optional combined verification, and trusted-device remembering.
102 + <p class="lead">
103 + Protect XWiki logins with authenticator app verification, recovery codes,
104 + trusted devices and administration controls for a safer rollout.
17 17   </p>
18 18  
19 - <ul class="product-highlights">
20 - <li>Works with the standard XWiki authentication flow</li>
21 - <li>Supports app codes, email codes, or both</li>
22 - <li>Helps protect administrator and remote-access accounts</li>
107 + <ul class="benefits">
108 + <li><strong>Extension from €95/year</strong></li>
109 + <li><strong>Basic setup from €150</strong></li>
110 + <li>MFA rollout support available</li>
23 23   </ul>
24 24  
25 - <p class="card-link">
26 - <a class="btn btn-secondary" href="$xwiki.getURL('products.xwiki-two-factor-authentication')">
27 - View extension
28 - </a>
113 + <div class="hero-actions">
114 + <a class="btn btn-primary" href="$xwiki.getURL('contact.WebHome')">Ask about this extension</a>
115 + <a class="btn btn-secondary" href="$xwiki.getURL('pricing.WebHome')#common-packages">View MFA setup price</a>
116 + </div>
117 + </div>
118 +</section>
119 +
120 +<section aria-labelledby="overview-title">
121 + <div class="container">
122 + <div class="product-layout">
123 + <article class="product-summary-card">
124 + <h2 id="overview-title">Two-factor authentication built into XWiki</h2>
125 +
126 + <p>
127 + XWiki Two-Factor Authentication adds an additional verification step to the standard
128 + XWiki login flow. Users continue to sign in with their normal username and password,
129 + then confirm access with a time-based code from an authenticator application.
130 + </p>
131 +
132 + <p>
133 + The application has evolved beyond a simple login-code screen. It supports global
134 + enforcement, recovery codes, trusted devices, user self-service, administrator
135 + reset actions and an overview for monitoring adoption.
136 + </p>
137 + </article>
138 +
139 + <aside class="product-info-card" aria-labelledby="quick-facts-title">
140 + <h3 id="quick-facts-title">Quick facts</h3>
141 + <ul>
142 + <li>Works with the standard XWiki login flow</li>
143 + <li>Supports TOTP authenticator applications</li>
144 + <li>Can require additional verification for all users</li>
145 + <li>Includes one-time recovery codes</li>
146 + <li>Can remember trusted browsers or devices</li>
147 + <li>Includes user self-service controls</li>
148 + <li>Includes an administration overview</li>
149 + </ul>
150 + </aside>
151 + </div>
152 + </div>
153 +</section>
154 +
155 +<section aria-labelledby="capabilities-title">
156 + <div class="container">
157 + <h2 id="capabilities-title">Main capabilities</h2>
158 +
159 + <p class="section-intro">
160 + A focused set of authentication protection features for stronger XWiki account security
161 + without replacing the familiar login experience.
29 29   </p>
163 +
164 + <div class="product-feature-grid">
165 + #foreach ($entry in $mainCapabilityItems)
166 + <article class="product-feature">
167 + <div class="card-heading">
168 + <div class="feature-icon">
169 + <i class="fa fa-$entry.icon" aria-hidden="true"></i>
170 + </div>
171 + <h3>$entry.title</h3>
172 + </div>
173 +
174 + <p>$entry.content</p>
175 + </article>
176 + #end
177 + </div>
30 30   </div>
31 -</article>
179 +</section>
180 +
181 +<section class="product-section-muted" aria-labelledby="security-title">
182 + <div class="container">
183 + <div class="product-layout">
184 + <article class="product-summary-card">
185 + <h2 id="security-title">Useful for XWiki security and access protection</h2>
186 +
187 + <p>
188 + Many organizations use XWiki to store internal documentation, procedures, operational
189 + knowledge and business-critical information. Adding an additional authentication factor helps
190 + reduce the risk of account compromise when a password is exposed or reused.
191 + </p>
192 +
193 + <p>
194 + The extension is especially useful for protecting administrator accounts, remote users,
195 + private knowledge bases and customer or partner portals.
196 + </p>
197 + </article>
198 +
199 + <aside class="product-info-card" aria-labelledby="use-cases-title">
200 + <h3 id="use-cases-title">Typical use cases</h3>
201 + <ul>
202 + <li>Administrator account protection</li>
203 + <li>Internal knowledge base security</li>
204 + <li>Private documentation platforms</li>
205 + <li>Remote user access protection</li>
206 + <li>Customer or partner portals</li>
207 + <li>Security review, MFA rollout and compliance readiness</li>
208 + </ul>
209 + </aside>
210 + </div>
211 + </div>
212 +</section>
213 +
214 +<section aria-labelledby="admin-experience-title">
215 + <div class="container">
216 + <h2 id="admin-experience-title">Administrator configuration and monitoring</h2>
217 +
218 + <p class="section-intro">
219 + Administrators can configure the policy, define recovery options and monitor adoption
220 + from the XWiki Administration section.
221 + </p>
222 +
223 + <div class="product-feature-grid">
224 + #foreach ($entry in $adminExperienceItems)
225 + <article class="product-feature">
226 + <div class="card-heading">
227 + <div class="feature-icon">
228 + <i class="fa fa-$entry.icon" aria-hidden="true"></i>
229 + </div>
230 + <h3>$entry.title</h3>
231 + </div>
232 +
233 + <p>$entry.content</p>
234 + </article>
235 + #end
236 + </div>
237 +
238 +{{/html}}
239 +
240 +{{gallery}}
241 +[[image:mfa-admin-configuration.png]]
242 +[[image:mfa-admin-overview.png]]
243 +[[image:mfa-admin-full.png]]
244 +{{/gallery}}
245 +
246 +{{html clean="false"}}
247 +
248 + <p class="product-gallery-caption">
249 + Administration screens for configuring the policy and reviewing adoption across users.
250 + </p>
251 + </div>
252 +</section>
253 +
254 +<section class="product-section-muted" aria-labelledby="user-experience-title">
255 + <div class="container">
256 + <h2 id="user-experience-title">User setup and login verification</h2>
257 +
258 + <p class="section-intro">
259 + Users can configure the authenticator app from their profile or during the enforced setup flow,
260 + then verify future logins with a generated code.
261 + </p>
262 +
263 + <div class="product-feature-grid">
264 + #foreach ($entry in $userExperienceItems)
265 + <article class="product-feature">
266 + <div class="card-heading">
267 + <div class="feature-icon">
268 + <i class="fa fa-$entry.icon" aria-hidden="true"></i>
269 + </div>
270 + <h3>$entry.title</h3>
271 + </div>
272 +
273 + <p>$entry.content</p>
274 + </article>
275 + #end
276 + </div>
277 +
278 +{{/html}}
279 +
280 +{{gallery}}
281 +[[image:mfa-user-setup-qr.png]]
282 +[[image:mfa-login-verification-setup.png]]
283 +[[image:mfa-login-verification-code.png]]
284 +{{/gallery}}
285 +
286 +{{html clean="false"}}
287 +
288 + <p class="product-gallery-caption">
289 + User setup, enforced configuration and login verification screens.
290 + </p>
291 + </div>
292 +</section>
293 +
294 +<section aria-labelledby="self-service-title">
295 + <div class="container">
296 + <h2 id="self-service-title">Recovery codes and trusted devices</h2>
297 +
298 + <p class="section-intro">
299 + Recovery codes and trusted devices help balance stronger access protection with a smoother user experience.
300 + </p>
301 +
302 + <div class="product-feature-grid">
303 + #foreach ($entry in $selfServiceItems)
304 + <article class="product-feature">
305 + <div class="card-heading">
306 + <div class="feature-icon">
307 + <i class="fa fa-$entry.icon" aria-hidden="true"></i>
308 + </div>
309 + <h3>$entry.title</h3>
310 + </div>
311 +
312 + <p>$entry.content</p>
313 + </article>
314 + #end
315 + </div>
316 +
317 +{{/html}}
318 +
319 +{{gallery}}
320 +[[image:mfa-user-profile-overview.png]]
321 +[[image:mfa-recovery-codes-not-generated.png]]
322 +[[image:mfa-recovery-codes-generated.png]]
323 +[[image:mfa-trusted-devices.png]]
324 +[[image:mfa-user-profile-full.png]]
325 +{{/gallery}}
326 +
327 +{{html clean="false"}}
328 +
329 + <p class="product-gallery-caption">
330 + User profile screens for recovery codes, trusted devices and self-service management.
331 + </p>
332 + </div>
333 +</section>
334 +
335 +<section class="product-section-muted" aria-labelledby="admin-support-title">
336 + <div class="container">
337 + <h2 id="admin-support-title">Administrator support and user recovery</h2>
338 +
339 + <p class="section-intro">
340 + Administrators can help users recover from lost devices or restart setup when needed.
341 + </p>
342 +
343 + <div class="product-feature-grid">
344 + #foreach ($entry in $adminSupportItems)
345 + <article class="product-feature">
346 + <div class="card-heading">
347 + <div class="feature-icon">
348 + <i class="fa fa-$entry.icon" aria-hidden="true"></i>
349 + </div>
350 + <h3>$entry.title</h3>
351 + </div>
352 +
353 + <p>$entry.content</p>
354 + </article>
355 + #end
356 + </div>
357 +
358 +{{/html}}
359 +
360 +{{gallery}}
361 +[[image:mfa-admin-user-management.png]]
362 +{{/gallery}}
363 +
364 +{{html clean="false"}}
365 +
366 + <p class="product-gallery-caption">
367 + Administrator view for checking and resetting a user setup.
368 + </p>
369 + </div>
370 +</section>
371 +
372 +<section aria-labelledby="faq-title">
373 + <div class="container">
374 + <h2 id="faq-title">Frequently asked questions</h2>
375 +
376 + <p class="section-intro">
377 + Common questions about how the extension works, how users configure it and how administrators can manage rollout and recovery.
378 + </p>
379 +
380 + <div class="resource-content">
381 + <details class="resource-faq-item">
382 + <summary>Does this extension replace the standard XWiki login?</summary>
383 + <p>
384 + No. Users still sign in with their normal XWiki username and password. The extension adds
385 + an additional verification step after the standard login check.
386 + </p>
387 + </details>
388 +
389 + <details class="resource-faq-item">
390 + <summary>Which verification method is used?</summary>
391 + <p>
392 + Users verify access with time-based codes generated by an authenticator application.
393 + The setup page provides a QR code and a manual setup key.
394 + </p>
395 + </details>
396 +
397 + <details class="resource-faq-item">
398 + <summary>Can the second verification step be required for all users?</summary>
399 + <p>
400 + Yes. Administrators can make the verification step optional or required for all users
401 + from the XWiki Administration section.
402 + </p>
403 + </details>
404 +
405 + <details class="resource-faq-item">
406 + <summary>What happens if a user loses access to the authenticator app?</summary>
407 + <p>
408 + Recovery codes can provide backup access when enabled. Administrators can also reset
409 + the user setup so the configuration process can be restarted.
410 + </p>
411 + </details>
412 +
413 + <details class="resource-faq-item">
414 + <summary>Can trusted browsers or devices be disabled?</summary>
415 + <p>
416 + Yes. Administrators can configure how long trusted devices remain valid. Setting the
417 + trusted-device duration to 0 disables this option.
418 + </p>
419 + </details>
420 +
421 + <details class="resource-faq-item">
422 + <summary>Is this only a basic 2FA login-code screen?</summary>
423 + <p>
424 + No. The main login mechanism is two-factor authentication, but the application also includes
425 + features needed for a safer organization-wide rollout: enforcement policy, recovery codes,
426 + trusted devices, user self-service, administrator monitoring and administrator reset actions.
427 + </p>
428 + </details>
429 +
430 + <details class="resource-faq-item">
431 + <summary>Is this enough for compliance on its own?</summary>
432 + <p>
433 + No. This extension provides an important access-protection control, but it should be part
434 + of a broader security and compliance approach that includes permissions, upgrades,
435 + infrastructure, monitoring and operational procedures.
436 + </p>
437 + </details>
438 + </div>
439 + </div>
440 +</section>
441 +
442 +<section class="product-section-muted" aria-labelledby="rollout-title">
443 + <div class="container">
444 + <div class="product-layout">
445 + <article class="product-summary-card">
446 + <h2 id="rollout-title">Rollout recommendations</h2>
447 +
448 + <p>
449 + For a smooth rollout, start with a small administrator or pilot group before requiring
450 + the additional verification step for everyone. This helps validate the configuration,
451 + prepare user communication and reduce support issues.
452 + </p>
453 +
454 + <ol class="process-list">
455 + #foreach ($entry in $rolloutItems)
456 + <li>
457 + <strong>$entry.title</strong>
458 + $entry.content
459 + </li>
460 + #end
461 + </ol>
462 + </article>
463 +
464 + <aside class="product-info-card" aria-labelledby="planning-title">
465 + <h3 id="planning-title">Useful information before installation</h3>
466 +
467 + <p class="product-card-note">
468 + These details help evaluate compatibility, rollout scope and configuration options.
469 + </p>
470 +
471 + <ul>
472 + <li>XWiki version</li>
473 + <li>Single wiki or wiki farm with subwikis</li>
474 + <li>Current authentication setup</li>
475 + <li>Optional or required rollout policy</li>
476 + <li>Trusted-device policy</li>
477 + <li>Recovery-code policy</li>
478 + <li>Rollout communication needs</li>
479 + </ul>
480 + </aside>
481 + </div>
482 + </div>
483 +</section>
484 +
485 +<section class="cta-section" aria-labelledby="cta-title">
486 + <div class="container">
487 + <div class="cta-panel">
488 + <h2 id="cta-title">Interested in using this extension?</h2>
489 +
490 + <p>
491 + Send a short message with your XWiki version, current authentication setup and rollout goal.
492 + </p>
493 +
494 + <a class="btn btn-primary" href="$xwiki.getURL('contact.WebHome')">Contact Agnease</a>
495 + <a class="btn btn-secondary" href="$xwiki.getURL('pricing.WebHome')#common-packages">View MFA setup price</a>
496 + </div>
497 + </div>
498 +</section>
499 +
500 +{{/html}}
501 +{{/velocity}}
2fa-authenticator.png
Author
... ... @@ -1,0 +1,1 @@
1 +XWiki.Admin
Size
... ... @@ -1,0 +1,1 @@
1 +1.1 MB
Content
mfa-admin-configuration.png
Author
... ... @@ -1,0 +1,1 @@
1 +XWiki.Admin
Size
... ... @@ -1,0 +1,1 @@
1 +125.3 KB
Content
mfa-admin-full.png
Author
... ... @@ -1,0 +1,1 @@
1 +XWiki.Admin
Size
... ... @@ -1,0 +1,1 @@
1 +184.3 KB
Content
mfa-admin-overview.png
Author
... ... @@ -1,0 +1,1 @@
1 +XWiki.Admin
Size
... ... @@ -1,0 +1,1 @@
1 +64.7 KB
Content
mfa-admin-user-management.png
Author
... ... @@ -1,0 +1,1 @@
1 +XWiki.Admin
Size
... ... @@ -1,0 +1,1 @@
1 +90.8 KB
Content
mfa-login-verification-code.png
Author
... ... @@ -1,0 +1,1 @@
1 +XWiki.Admin
Size
... ... @@ -1,0 +1,1 @@
1 +23.6 KB
Content
mfa-login-verification-setup.png
Author
... ... @@ -1,0 +1,1 @@
1 +XWiki.Admin
Size
... ... @@ -1,0 +1,1 @@
1 +115.9 KB
Content
mfa-recovery-codes-generated.png
Author
... ... @@ -1,0 +1,1 @@
1 +XWiki.Admin
Size
... ... @@ -1,0 +1,1 @@
1 +38.5 KB
Content
mfa-recovery-codes-not-generated.png
Author
... ... @@ -1,0 +1,1 @@
1 +XWiki.Admin
Size
... ... @@ -1,0 +1,1 @@
1 +27.0 KB
Content
mfa-trusted-devices.png
Author
... ... @@ -1,0 +1,1 @@
1 +XWiki.Admin
Size
... ... @@ -1,0 +1,1 @@
1 +59.1 KB
Content
mfa-user-profile-full.png
Author
... ... @@ -1,0 +1,1 @@
1 +XWiki.Admin
Size
... ... @@ -1,0 +1,1 @@
1 +197.5 KB
Content
mfa-user-profile-overview.png
Author
... ... @@ -1,0 +1,1 @@
1 +XWiki.Admin
Size
... ... @@ -1,0 +1,1 @@
1 +193.4 KB
Content
mfa-user-setup-qr.png
Author
... ... @@ -1,0 +1,1 @@
1 +XWiki.Admin
Size
... ... @@ -1,0 +1,1 @@
1 +176.6 KB
Content
Agnease.Code.SEODetailsClass[0]
metaDescription
... ... @@ -1,0 +1,1 @@
1 +Agnease Two-Factor Authentication for XWiki adds a second login verification step with authenticator app codes, email codes, combined verification and trusted-device remembering.
metaTitle
... ... @@ -1,0 +1,1 @@
1 +XWiki Two-Factor Authentication with 2FA and MFA Support | Agnease