Last modified by Alex Cotiuga on 2026/07/13 06:59

From version 9.1
edited by Alex Cotiuga
on 2026/06/24 14:23
Change comment: Rollback to version 6.10
To version 30.5
edited by Alex Cotiuga
on 2026/07/13 06:57
Change comment: There is no comment for this version

Summary

Details

Page properties
Default language
... ... @@ -1,1 +1,0 @@
1 -en
Hidden
... ... @@ -1,1 +1,1 @@
1 -false
1 +true
Content
... ... @@ -1,25 +1,117 @@
1 1  {{velocity}}
2 2  #set ($discard = $xwiki.ssx.use('PublicWebSite.WebHome'))
3 -#set ($discard = $xwiki.ssx.use('products.WebHome'))
3 +
4 +#set ($mainCapabilityItems = [{
5 + 'title': 'Second verification step',
6 + 'icon': 'key',
7 + 'content': 'Add an additional verification screen after the normal XWiki username and password login.'
8 +},{
9 + 'title': 'Authenticator app codes',
10 + 'icon': 'mobile',
11 + 'content': 'Let users verify access with time-based TOTP codes generated by authenticator applications.'
12 +},{
13 + 'title': 'Recovery and trusted devices',
14 + 'icon': 'shield',
15 + 'content': 'Provide backup access with recovery codes and reduce repeated prompts on trusted browsers.'
16 +}])
17 +
18 +#set ($adminExperienceItems = [{
19 + 'title': 'Rollout policy',
20 + 'icon': 'cog',
21 + 'content': 'Make additional verification optional at first or required for all users from the XWiki Administration section.'
22 +},{
23 + 'title': 'Configuration options',
24 + 'icon': 'sliders',
25 + 'content': 'Set the authenticator issuer name, recovery-code count and trusted-device duration.'
26 +},{
27 + 'title': 'Administration overview',
28 + 'icon': 'table',
29 + 'content': 'Review adoption with summary indicators and a filterable Live Data table.'
30 +}])
31 +
32 +#set ($userExperienceItems = [{
33 + 'title': 'Self-service setup',
34 + 'icon': 'qrcode',
35 + 'content': 'Users configure the second verification step from their profile by scanning a QR code or entering the setup key manually.'
36 +},{
37 + 'title': 'Login verification',
38 + 'icon': 'sign-in',
39 + 'content': 'After the normal login, users enter the verification code generated by their authenticator app.'
40 +},{
41 + 'title': 'Trusted browser option',
42 + 'icon': 'desktop',
43 + 'content': 'Users can trust the current browser for the configured duration after successful verification.'
44 +}])
45 +
46 +#set ($selfServiceItems = [{
47 + 'title': 'Recovery codes',
48 + 'icon': 'life-ring',
49 + 'content': 'Recovery codes provide backup access when a user loses access to the authenticator application.'
50 +},{
51 + 'title': 'Trusted devices',
52 + 'icon': 'desktop',
53 + 'content': 'Trusted devices can be reviewed and removed from the user profile.'
54 +},{
55 + 'title': 'Profile management',
56 + 'icon': 'user',
57 + 'content': 'Users can review status, generate recovery codes, manage trusted devices and reset their setup.'
58 +}])
59 +
60 +#set ($adminSupportItems = [{
61 + 'title': 'User status',
62 + 'icon': 'user',
63 + 'content': 'Administrators can open a user profile and check the verification status for that account.'
64 +},{
65 + 'title': 'Setup reset',
66 + 'icon': 'refresh',
67 + 'content': 'Administrators can reset the setup when a user needs to restart the configuration process.'
68 +},{
69 + 'title': 'Controlled recovery',
70 + 'icon': 'unlock-alt',
71 + 'content': 'Resetting the setup removes the authenticator configuration, recovery codes and trusted devices for that user.'
72 +}])
73 +
74 +#set ($rolloutItems = [{
75 + 'title': 'Start with a pilot group',
76 + 'content': 'Test the extension with administrators or a small user group before enabling it widely.'
77 +},{
78 + 'title': 'Define the rollout policy',
79 + 'content': 'Decide whether additional verification should be optional at first or required for all users.'
80 +},{
81 + 'title': 'Configure recovery options',
82 + 'content': 'Choose the number of recovery codes and whether trusted devices should be allowed.'
83 +},{
84 + 'title': 'Inform users',
85 + 'content': 'Explain how users configure the authenticator app, save recovery codes and manage trusted devices.'
86 +},{
87 + 'title': 'Monitor adoption',
88 + 'content': 'Use the administration overview to identify users who still need to configure protection.'
89 +}])
90 +
4 4  {{html clean="false"}}
5 5  
6 -<section class="hero hero-centered" aria-labelledby="hero-title">
93 +<section class="hero hero-centered" aria-labelledby="product-title">
7 7   <div class="container hero-inner">
8 8   <div class="hero-kicker">
9 9   <i class="fa fa-lock" aria-hidden="true"></i>
10 - XWiki 2FA and MFA
97 + XWiki 2FA with MFA rollout support
11 11   </div>
12 12  
13 13   <h1 id="product-title">XWiki Two-Factor Authentication</h1>
14 14  
15 15   <p class="lead">
16 - Protect XWiki logins with a second verification step using authenticator app codes,
17 - email verification codes, or both.
103 + Protect XWiki logins with authenticator app verification, recovery codes,
104 + trusted devices and administration controls for a safer rollout.
18 18   </p>
19 19  
107 + <div class="product-card-kicker">
108 + <i class="fa fa-tag" aria-hidden="true"></i>
109 + Extension from €95/year · Basic setup from €150
110 + </div>
111 +
20 20   <div class="hero-actions">
21 21   <a class="btn btn-primary" href="$xwiki.getURL('contact.WebHome')">Ask about this extension</a>
22 - <a class="btn btn-secondary" href="$xwiki.getURL('products.WebHome')">View all products</a>
114 + <a class="btn btn-secondary" href="$xwiki.getURL('pricing.WebHome')#common-packages">View MFA setup price</a>
23 23   </div>
24 24   </div>
25 25  </section>
... ... @@ -31,20 +31,16 @@
31 31   <h2 id="overview-title">Two-factor authentication built into XWiki</h2>
32 32  
33 33   <p>
34 - XWiki Two-Factor Authentication adds an additional verification screen after the standard
35 - XWiki username and password login. It improves account protection without replacing the
36 - familiar XWiki authentication flow.
126 + XWiki Two-Factor Authentication adds an additional verification step to the standard
127 + XWiki login flow. Users continue to sign in with their normal username and password,
128 + then confirm access with a time-based code from an authenticator application.
37 37   </p>
38 38  
39 39   <p>
40 - Users can verify access with TOTP codes generated by an authenticator app, with one-time
41 - codes delivered by email, or with a combined setup requiring both methods.
132 + The application has evolved beyond a simple login-code screen. It supports global
133 + enforcement, recovery codes, trusted devices, user self-service, administrator
134 + reset actions and an overview for monitoring adoption.
42 42   </p>
43 -
44 - <p>
45 - Trusted browsers or devices can be remembered for a configured period, reducing repeated
46 - verification prompts on known clients while still requiring verification from new or untrusted ones.
47 - </p>
48 48   </article>
49 49  
50 50   <aside class="product-info-card" aria-labelledby="quick-facts-title">
... ... @@ -51,11 +51,12 @@
51 51   <h3 id="quick-facts-title">Quick facts</h3>
52 52   <ul>
53 53   <li>Works with the standard XWiki login flow</li>
54 - <li>Supports authenticator app codes using TOTP</li>
55 - <li>Supports email-delivered one-time verification codes</li>
56 - <li>Can require app code and email code together</li>
142 + <li>Supports TOTP authenticator applications</li>
143 + <li>Can require additional verification for all users</li>
144 + <li>Includes one-time recovery codes</li>
57 57   <li>Can remember trusted browsers or devices</li>
58 - <li>Includes administration and user setup controls</li>
146 + <li>Includes user self-service controls</li>
147 + <li>Includes an administration overview</li>
59 59   </ul>
60 60   </aside>
61 61   </div>
... ... @@ -62,91 +62,330 @@
62 62   </div>
63 63  </section>
64 64  
65 -<section aria-labelledby="features-title">
154 +<section aria-labelledby="capabilities-title">
66 66   <div class="container">
67 - <h2 id="features-title">Main capabilities</h2>
156 + <h2 id="capabilities-title">Main capabilities</h2>
68 68  
69 69   <p class="section-intro">
70 - A focused set of MFA/2FA features for stronger XWiki account protection without changing the standard login experience.
159 + A focused set of authentication protection features for stronger XWiki account security
160 + without replacing the familiar login experience.
71 71   </p>
72 72  
73 73   <div class="product-feature-grid">
74 - <article class="product-feature">
75 - <div class="card-heading">
76 - <div class="feature-icon">
77 - <i class="fa fa-key" aria-hidden="true"></i>
164 + #foreach ($entry in $mainCapabilityItems)
165 + <article class="product-feature">
166 + <div class="card-heading">
167 + <div class="feature-icon">
168 + <i class="fa fa-$entry.icon" aria-hidden="true"></i>
169 + </div>
170 + <h3>$entry.title</h3>
78 78   </div>
79 - <h3>Second verification step</h3>
80 - </div>
81 81  
173 + <p>$entry.content</p>
174 + </article>
175 + #end
176 + </div>
177 + </div>
178 +</section>
179 +
180 +<section class="product-section-muted" aria-labelledby="security-title">
181 + <div class="container">
182 + <div class="product-layout">
183 + <article class="product-summary-card">
184 + <h2 id="security-title">Useful for XWiki security and access protection</h2>
185 +
82 82   <p>
83 - After username and password verification, users complete an additional step before accessing XWiki.
84 - The flow can require one verification method or both app and email codes.
187 + Many organizations use XWiki to store internal documentation, procedures, operational
188 + knowledge and business-critical information. Adding an additional authentication factor helps
189 + reduce the risk of account compromise when a password is exposed or reused.
85 85   </p>
191 +
192 + <p>
193 + The extension is especially useful for protecting administrator accounts, remote users,
194 + private knowledge bases and customer or partner portals.
195 + </p>
86 86   </article>
87 87  
88 - <article class="product-feature">
89 - <div class="card-heading">
90 - <div class="feature-icon">
91 - <i class="fa fa-mobile" aria-hidden="true"></i>
198 + <aside class="product-info-card" aria-labelledby="use-cases-title">
199 + <h3 id="use-cases-title">Typical use cases</h3>
200 + <ul>
201 + <li>Administrator account protection</li>
202 + <li>Internal knowledge base security</li>
203 + <li>Private documentation platforms</li>
204 + <li>Remote user access protection</li>
205 + <li>Customer or partner portals</li>
206 + <li>Security review, MFA rollout and compliance readiness</li>
207 + </ul>
208 + </aside>
209 + </div>
210 + </div>
211 +</section>
212 +
213 +<section aria-labelledby="admin-experience-title">
214 + <div class="container">
215 + <h2 id="admin-experience-title">Administrator configuration and monitoring</h2>
216 +
217 + <p class="section-intro">
218 + Administrators can configure the policy, define recovery options and monitor adoption
219 + from the XWiki Administration section.
220 + </p>
221 +
222 + <div class="product-feature-grid">
223 + #foreach ($entry in $adminExperienceItems)
224 + <article class="product-feature">
225 + <div class="card-heading">
226 + <div class="feature-icon">
227 + <i class="fa fa-$entry.icon" aria-hidden="true"></i>
228 + </div>
229 + <h3>$entry.title</h3>
92 92   </div>
93 - <h3>Authenticator app codes</h3>
94 - </div>
95 95  
232 + <p>$entry.content</p>
233 + </article>
234 + #end
235 + </div>
236 +
237 +{{/html}}
238 +
239 +{{gallery}}
240 +[[image:mfa-admin-configuration.png]]
241 +[[image:mfa-admin-overview.png]]
242 +[[image:mfa-admin-full.png]]
243 +{{/gallery}}
244 +
245 +{{html clean="false"}}
246 +
247 + <p class="product-gallery-caption">
248 + Administration screens for configuring the policy and reviewing adoption across users.
249 + </p>
250 + </div>
251 +</section>
252 +
253 +<section class="product-section-muted" aria-labelledby="user-experience-title">
254 + <div class="container">
255 + <h2 id="user-experience-title">User setup and login verification</h2>
256 +
257 + <p class="section-intro">
258 + Users can configure the authenticator app from their profile or during the enforced setup flow,
259 + then verify future logins with a generated code.
260 + </p>
261 +
262 + <div class="product-feature-grid">
263 + #foreach ($entry in $userExperienceItems)
264 + <article class="product-feature">
265 + <div class="card-heading">
266 + <div class="feature-icon">
267 + <i class="fa fa-$entry.icon" aria-hidden="true"></i>
268 + </div>
269 + <h3>$entry.title</h3>
270 + </div>
271 +
272 + <p>$entry.content</p>
273 + </article>
274 + #end
275 + </div>
276 +
277 +{{/html}}
278 +
279 +{{gallery}}
280 +[[image:mfa-user-setup-qr.png]]
281 +[[image:mfa-login-verification-setup.png]]
282 +[[image:mfa-login-verification-code.png]]
283 +{{/gallery}}
284 +
285 +{{html clean="false"}}
286 +
287 + <p class="product-gallery-caption">
288 + User setup, enforced configuration and login verification screens.
289 + </p>
290 + </div>
291 +</section>
292 +
293 +<section aria-labelledby="self-service-title">
294 + <div class="container">
295 + <h2 id="self-service-title">Recovery codes and trusted devices</h2>
296 +
297 + <p class="section-intro">
298 + Recovery codes and trusted devices help balance stronger access protection with a smoother user experience.
299 + </p>
300 +
301 + <div class="product-feature-grid">
302 + #foreach ($entry in $selfServiceItems)
303 + <article class="product-feature">
304 + <div class="card-heading">
305 + <div class="feature-icon">
306 + <i class="fa fa-$entry.icon" aria-hidden="true"></i>
307 + </div>
308 + <h3>$entry.title</h3>
309 + </div>
310 +
311 + <p>$entry.content</p>
312 + </article>
313 + #end
314 + </div>
315 +
316 +{{/html}}
317 +
318 +{{gallery}}
319 +[[image:mfa-user-profile-overview.png]]
320 +[[image:mfa-recovery-codes-not-generated.png]]
321 +[[image:mfa-recovery-codes-generated.png]]
322 +[[image:mfa-trusted-devices.png]]
323 +[[image:mfa-user-profile-full.png]]
324 +{{/gallery}}
325 +
326 +{{html clean="false"}}
327 +
328 + <p class="product-gallery-caption">
329 + User profile screens for recovery codes, trusted devices and self-service management.
330 + </p>
331 + </div>
332 +</section>
333 +
334 +<section class="product-section-muted" aria-labelledby="admin-support-title">
335 + <div class="container">
336 + <h2 id="admin-support-title">Administrator support and user recovery</h2>
337 +
338 + <p class="section-intro">
339 + Administrators can help users recover from lost devices or restart setup when needed.
340 + </p>
341 +
342 + <div class="product-feature-grid">
343 + #foreach ($entry in $adminSupportItems)
344 + <article class="product-feature">
345 + <div class="card-heading">
346 + <div class="feature-icon">
347 + <i class="fa fa-$entry.icon" aria-hidden="true"></i>
348 + </div>
349 + <h3>$entry.title</h3>
350 + </div>
351 +
352 + <p>$entry.content</p>
353 + </article>
354 + #end
355 + </div>
356 +
357 +{{/html}}
358 +
359 +{{gallery}}
360 +[[image:mfa-admin-user-management.png]]
361 +{{/gallery}}
362 +
363 +{{html clean="false"}}
364 +
365 + <p class="product-gallery-caption">
366 + Administrator view for checking and resetting a user setup.
367 + </p>
368 + </div>
369 +</section>
370 +
371 +<section aria-labelledby="faq-title">
372 + <div class="container">
373 + <h2 id="faq-title">Frequently asked questions</h2>
374 +
375 + <p class="section-intro">
376 + Common questions about how the extension works, how users configure it and how administrators can manage rollout and recovery.
377 + </p>
378 +
379 + <div class="resource-content">
380 + <details class="resource-faq-item">
381 + <summary>Does this extension replace the standard XWiki login?</summary>
96 96   <p>
97 - Users can verify access with TOTP codes generated by authenticator applications on mobile or desktop devices.
383 + No. Users still sign in with their normal XWiki username and password. The extension adds
384 + an additional verification step after the standard login check.
98 98   </p>
99 - </article>
386 + </details>
100 100  
101 - <article class="product-feature">
102 - <div class="card-heading">
103 - <div class="feature-icon">
104 - <i class="fa fa-envelope-o" aria-hidden="true"></i>
105 - </div>
106 - <h3>Email verification codes</h3>
107 - </div>
388 + <details class="resource-faq-item">
389 + <summary>Which verification method is used?</summary>
390 + <p>
391 + Users verify access with time-based codes generated by an authenticator application.
392 + The setup page provides a QR code and a manual setup key.
393 + </p>
394 + </details>
108 108  
396 + <details class="resource-faq-item">
397 + <summary>Can the second verification step be required for all users?</summary>
109 109   <p>
110 - Users can receive one-time verification codes by email when an authenticator app is not available or preferred.
399 + Yes. Administrators can make the verification step optional or required for all users
400 + from the XWiki Administration section.
111 111   </p>
112 - </article>
402 + </details>
403 +
404 + <details class="resource-faq-item">
405 + <summary>What happens if a user loses access to the authenticator app?</summary>
406 + <p>
407 + Recovery codes can provide backup access when enabled. Administrators can also reset
408 + the user setup so the configuration process can be restarted.
409 + </p>
410 + </details>
411 +
412 + <details class="resource-faq-item">
413 + <summary>Can trusted browsers or devices be disabled?</summary>
414 + <p>
415 + Yes. Administrators can configure how long trusted devices remain valid. Setting the
416 + trusted-device duration to 0 disables this option.
417 + </p>
418 + </details>
419 +
420 + <details class="resource-faq-item">
421 + <summary>Is this only a basic 2FA login-code screen?</summary>
422 + <p>
423 + No. The main login mechanism is two-factor authentication, but the application also includes
424 + features needed for a safer organization-wide rollout: enforcement policy, recovery codes,
425 + trusted devices, user self-service, administrator monitoring and administrator reset actions.
426 + </p>
427 + </details>
428 +
429 + <details class="resource-faq-item">
430 + <summary>Is this enough for compliance on its own?</summary>
431 + <p>
432 + No. This extension provides an important access-protection control, but it should be part
433 + of a broader security and compliance approach that includes permissions, upgrades,
434 + infrastructure, monitoring and operational procedures.
435 + </p>
436 + </details>
113 113   </div>
114 114   </div>
115 115  </section>
116 116  
117 -<section class="product-section-muted" aria-labelledby="security-title">
441 +<section class="product-section-muted" aria-labelledby="rollout-title">
118 118   <div class="container">
119 119   <div class="product-layout">
120 120   <article class="product-summary-card">
121 - <h2 id="security-title">Useful for XWiki security and NIS 2 readiness</h2>
445 + <h2 id="rollout-title">Rollout recommendations</h2>
122 122  
123 123   <p>
124 - Many organizations need multi-factor authentication for enterprise software, including internal
125 - knowledge bases, intranets, documentation platforms and systems containing operational procedures
126 - or sensitive business information.
448 + For a smooth rollout, start with a small administrator or pilot group before requiring
449 + the additional verification step for everyone. This helps validate the configuration,
450 + prepare user communication and reduce support issues.
127 127   </p>
128 128  
129 - <p>
130 - For organizations using XWiki, adding two-factor authentication directly to the standard login flow
131 - can help close a practical access-control gap. It can be useful for administrator accounts, remote users,
132 - private knowledge bases and broader security readiness initiatives such as NIS 2 preparation.
133 - </p>
453 + <ol class="process-list">
454 + #foreach ($entry in $rolloutItems)
455 + <li>
456 + <strong>$entry.title</strong>
457 + $entry.content
458 + </li>
459 + #end
460 + </ol>
461 + </article>
134 134  
135 - <p>
136 - This extension is not a complete compliance solution on its own, but it can provide an important
137 - technical control for protecting access to XWiki.
463 + <aside class="product-info-card" aria-labelledby="planning-title">
464 + <h3 id="planning-title">Useful information before installation</h3>
465 +
466 + <p class="product-card-note">
467 + These details help evaluate compatibility, rollout scope and configuration options.
138 138   </p>
139 - </article>
140 140  
141 - <aside class="product-info-card" aria-labelledby="security-controls-title">
142 - <h3 id="security-controls-title">Useful for</h3>
143 143   <ul>
144 - <li>XWiki 2FA rollout</li>
145 - <li>XWiki MFA adoption</li>
146 - <li>Administrator account protection</li>
147 - <li>Remote user access protection</li>
148 - <li>Private knowledge base security</li>
149 - <li>NIS 2 readiness initiatives</li>
471 + <li>XWiki version</li>
472 + <li>Single wiki or wiki farm with subwikis</li>
473 + <li>Current authentication setup</li>
474 + <li>Optional or required rollout policy</li>
475 + <li>Trusted-device policy</li>
476 + <li>Recovery-code policy</li>
477 + <li>Rollout communication needs</li>
150 150   </ul>
151 151   </aside>
152 152   </div>
... ... @@ -157,11 +157,13 @@
157 157   <div class="container">
158 158   <div class="cta-panel">
159 159   <h2 id="cta-title">Interested in using this extension?</h2>
488 +
160 160   <p>
161 - Send a short message with your XWiki version, authentication setup, and whether you need
162 - authenticator app codes, email verification codes, combined verification, or trusted-device remembering.
490 + Send a short message with your XWiki version, current authentication setup and rollout goal.
163 163   </p>
492 +
164 164   <a class="btn btn-primary" href="$xwiki.getURL('contact.WebHome')">Contact Agnease</a>
494 + <a class="btn btn-secondary" href="$xwiki.getURL('pricing.WebHome')#common-packages">View MFA setup price</a>
165 165   </div>
166 166   </div>
167 167  </section>
2fa-authenticator.png
Author
... ... @@ -1,0 +1,1 @@
1 +XWiki.Admin
Size
... ... @@ -1,0 +1,1 @@
1 +1.1 MB
Content
mfa-admin-configuration.png
Author
... ... @@ -1,0 +1,1 @@
1 +XWiki.Admin
Size
... ... @@ -1,0 +1,1 @@
1 +125.3 KB
Content
mfa-admin-full.png
Author
... ... @@ -1,0 +1,1 @@
1 +XWiki.Admin
Size
... ... @@ -1,0 +1,1 @@
1 +184.3 KB
Content
mfa-admin-overview.png
Author
... ... @@ -1,0 +1,1 @@
1 +XWiki.Admin
Size
... ... @@ -1,0 +1,1 @@
1 +64.7 KB
Content
mfa-admin-user-management.png
Author
... ... @@ -1,0 +1,1 @@
1 +XWiki.Admin
Size
... ... @@ -1,0 +1,1 @@
1 +90.8 KB
Content
mfa-login-verification-code.png
Author
... ... @@ -1,0 +1,1 @@
1 +XWiki.Admin
Size
... ... @@ -1,0 +1,1 @@
1 +23.6 KB
Content
mfa-login-verification-setup.png
Author
... ... @@ -1,0 +1,1 @@
1 +XWiki.Admin
Size
... ... @@ -1,0 +1,1 @@
1 +115.9 KB
Content
mfa-recovery-codes-generated.png
Author
... ... @@ -1,0 +1,1 @@
1 +XWiki.Admin
Size
... ... @@ -1,0 +1,1 @@
1 +38.5 KB
Content
mfa-recovery-codes-not-generated.png
Author
... ... @@ -1,0 +1,1 @@
1 +XWiki.Admin
Size
... ... @@ -1,0 +1,1 @@
1 +27.0 KB
Content
mfa-trusted-devices.png
Author
... ... @@ -1,0 +1,1 @@
1 +XWiki.Admin
Size
... ... @@ -1,0 +1,1 @@
1 +59.1 KB
Content
mfa-user-profile-full.png
Author
... ... @@ -1,0 +1,1 @@
1 +XWiki.Admin
Size
... ... @@ -1,0 +1,1 @@
1 +197.5 KB
Content
mfa-user-profile-overview.png
Author
... ... @@ -1,0 +1,1 @@
1 +XWiki.Admin
Size
... ... @@ -1,0 +1,1 @@
1 +193.4 KB
Content
mfa-user-setup-qr.png
Author
... ... @@ -1,0 +1,1 @@
1 +XWiki.Admin
Size
... ... @@ -1,0 +1,1 @@
1 +176.6 KB
Content