Last modified by Alex Cotiuga on 2026/07/13 06:59

From version 9.1
edited by Alex Cotiuga
on 2026/06/24 14:23
Change comment: Rollback to version 6.10
To version 30.6
edited by Alex Cotiuga
on 2026/07/13 06:59
Change comment: There is no comment for this version

Summary

Details

Page properties
Default language
... ... @@ -1,1 +1,0 @@
1 -en
Hidden
... ... @@ -1,1 +1,1 @@
1 -false
1 +true
Content
... ... @@ -1,25 +1,118 @@
1 1  {{velocity}}
2 2  #set ($discard = $xwiki.ssx.use('PublicWebSite.WebHome'))
3 -#set ($discard = $xwiki.ssx.use('products.WebHome'))
3 +
4 +#set ($mainCapabilityItems = [{
5 + 'title': 'Second verification step',
6 + 'icon': 'key',
7 + 'content': 'Add an additional verification screen after the normal XWiki username and password login.'
8 +},{
9 + 'title': 'Authenticator app codes',
10 + 'icon': 'mobile',
11 + 'content': 'Let users verify access with time-based TOTP codes generated by authenticator applications.'
12 +},{
13 + 'title': 'Recovery and trusted devices',
14 + 'icon': 'shield',
15 + 'content': 'Provide backup access with recovery codes and reduce repeated prompts on trusted browsers.'
16 +}])
17 +
18 +#set ($adminExperienceItems = [{
19 + 'title': 'Rollout policy',
20 + 'icon': 'cog',
21 + 'content': 'Make additional verification optional at first or required for all users from the XWiki Administration section.'
22 +},{
23 + 'title': 'Configuration options',
24 + 'icon': 'sliders',
25 + 'content': 'Set the authenticator issuer name, recovery-code count and trusted-device duration.'
26 +},{
27 + 'title': 'Administration overview',
28 + 'icon': 'table',
29 + 'content': 'Review adoption with summary indicators and a filterable Live Data table.'
30 +}])
31 +
32 +#set ($userExperienceItems = [{
33 + 'title': 'Self-service setup',
34 + 'icon': 'qrcode',
35 + 'content': 'Users configure the second verification step from their profile by scanning a QR code or entering the setup key manually.'
36 +},{
37 + 'title': 'Login verification',
38 + 'icon': 'sign-in',
39 + 'content': 'After the normal login, users enter the verification code generated by their authenticator app.'
40 +},{
41 + 'title': 'Trusted browser option',
42 + 'icon': 'desktop',
43 + 'content': 'Users can trust the current browser for the configured duration after successful verification.'
44 +}])
45 +
46 +#set ($selfServiceItems = [{
47 + 'title': 'Recovery codes',
48 + 'icon': 'life-ring',
49 + 'content': 'Recovery codes provide backup access when a user loses access to the authenticator application.'
50 +},{
51 + 'title': 'Trusted devices',
52 + 'icon': 'desktop',
53 + 'content': 'Trusted devices can be reviewed and removed from the user profile.'
54 +},{
55 + 'title': 'Profile management',
56 + 'icon': 'user',
57 + 'content': 'Users can review status, generate recovery codes, manage trusted devices and reset their setup.'
58 +}])
59 +
60 +#set ($adminSupportItems = [{
61 + 'title': 'User status',
62 + 'icon': 'user',
63 + 'content': 'Administrators can open a user profile and check the verification status for that account.'
64 +},{
65 + 'title': 'Setup reset',
66 + 'icon': 'refresh',
67 + 'content': 'Administrators can reset the setup when a user needs to restart the configuration process.'
68 +},{
69 + 'title': 'Controlled recovery',
70 + 'icon': 'unlock-alt',
71 + 'content': 'Resetting the setup removes the authenticator configuration, recovery codes and trusted devices for that user.'
72 +}])
73 +
74 +#set ($rolloutItems = [{
75 + 'title': 'Start with a pilot group',
76 + 'content': 'Test the extension with administrators or a small user group before enabling it widely.'
77 +},{
78 + 'title': 'Define the rollout policy',
79 + 'content': 'Decide whether additional verification should be optional at first or required for all users.'
80 +},{
81 + 'title': 'Configure recovery options',
82 + 'content': 'Choose the number of recovery codes and whether trusted devices should be allowed.'
83 +},{
84 + 'title': 'Inform users',
85 + 'content': 'Explain how users configure the authenticator app, save recovery codes and manage trusted devices.'
86 +},{
87 + 'title': 'Monitor adoption',
88 + 'content': 'Use the administration overview to identify users who still need to configure protection.'
89 +}])
90 +
4 4  {{html clean="false"}}
5 5  
6 -<section class="hero hero-centered" aria-labelledby="hero-title">
93 +<section class="hero hero-centered" aria-labelledby="product-title">
7 7   <div class="container hero-inner">
8 8   <div class="hero-kicker">
9 9   <i class="fa fa-lock" aria-hidden="true"></i>
10 - XWiki 2FA and MFA
97 + XWiki 2FA with MFA rollout support
11 11   </div>
12 12  
13 13   <h1 id="product-title">XWiki Two-Factor Authentication</h1>
14 14  
15 15   <p class="lead">
16 - Protect XWiki logins with a second verification step using authenticator app codes,
17 - email verification codes, or both.
103 + Protect XWiki logins with authenticator app verification, recovery codes,
104 + trusted devices and administration controls for a safer rollout.
18 18   </p>
19 19  
107 + <ul class="benefits">
108 + <li><strong>Extension from €95/year</strong></li>
109 + <li><strong>Basic setup from €150</strong></li>
110 + <li>MFA rollout support available</li>
111 + </ul>
112 +
20 20   <div class="hero-actions">
21 21   <a class="btn btn-primary" href="$xwiki.getURL('contact.WebHome')">Ask about this extension</a>
22 - <a class="btn btn-secondary" href="$xwiki.getURL('products.WebHome')">View all products</a>
115 + <a class="btn btn-secondary" href="$xwiki.getURL('pricing.WebHome')#common-packages">View MFA setup price</a>
23 23   </div>
24 24   </div>
25 25  </section>
... ... @@ -31,20 +31,16 @@
31 31   <h2 id="overview-title">Two-factor authentication built into XWiki</h2>
32 32  
33 33   <p>
34 - XWiki Two-Factor Authentication adds an additional verification screen after the standard
35 - XWiki username and password login. It improves account protection without replacing the
36 - familiar XWiki authentication flow.
127 + XWiki Two-Factor Authentication adds an additional verification step to the standard
128 + XWiki login flow. Users continue to sign in with their normal username and password,
129 + then confirm access with a time-based code from an authenticator application.
37 37   </p>
38 38  
39 39   <p>
40 - Users can verify access with TOTP codes generated by an authenticator app, with one-time
41 - codes delivered by email, or with a combined setup requiring both methods.
133 + The application has evolved beyond a simple login-code screen. It supports global
134 + enforcement, recovery codes, trusted devices, user self-service, administrator
135 + reset actions and an overview for monitoring adoption.
42 42   </p>
43 -
44 - <p>
45 - Trusted browsers or devices can be remembered for a configured period, reducing repeated
46 - verification prompts on known clients while still requiring verification from new or untrusted ones.
47 - </p>
48 48   </article>
49 49  
50 50   <aside class="product-info-card" aria-labelledby="quick-facts-title">
... ... @@ -51,11 +51,12 @@
51 51   <h3 id="quick-facts-title">Quick facts</h3>
52 52   <ul>
53 53   <li>Works with the standard XWiki login flow</li>
54 - <li>Supports authenticator app codes using TOTP</li>
55 - <li>Supports email-delivered one-time verification codes</li>
56 - <li>Can require app code and email code together</li>
143 + <li>Supports TOTP authenticator applications</li>
144 + <li>Can require additional verification for all users</li>
145 + <li>Includes one-time recovery codes</li>
57 57   <li>Can remember trusted browsers or devices</li>
58 - <li>Includes administration and user setup controls</li>
147 + <li>Includes user self-service controls</li>
148 + <li>Includes an administration overview</li>
59 59   </ul>
60 60   </aside>
61 61   </div>
... ... @@ -62,91 +62,330 @@
62 62   </div>
63 63  </section>
64 64  
65 -<section aria-labelledby="features-title">
155 +<section aria-labelledby="capabilities-title">
66 66   <div class="container">
67 - <h2 id="features-title">Main capabilities</h2>
157 + <h2 id="capabilities-title">Main capabilities</h2>
68 68  
69 69   <p class="section-intro">
70 - A focused set of MFA/2FA features for stronger XWiki account protection without changing the standard login experience.
160 + A focused set of authentication protection features for stronger XWiki account security
161 + without replacing the familiar login experience.
71 71   </p>
72 72  
73 73   <div class="product-feature-grid">
74 - <article class="product-feature">
75 - <div class="card-heading">
76 - <div class="feature-icon">
77 - <i class="fa fa-key" aria-hidden="true"></i>
165 + #foreach ($entry in $mainCapabilityItems)
166 + <article class="product-feature">
167 + <div class="card-heading">
168 + <div class="feature-icon">
169 + <i class="fa fa-$entry.icon" aria-hidden="true"></i>
170 + </div>
171 + <h3>$entry.title</h3>
78 78   </div>
79 - <h3>Second verification step</h3>
80 - </div>
81 81  
174 + <p>$entry.content</p>
175 + </article>
176 + #end
177 + </div>
178 + </div>
179 +</section>
180 +
181 +<section class="product-section-muted" aria-labelledby="security-title">
182 + <div class="container">
183 + <div class="product-layout">
184 + <article class="product-summary-card">
185 + <h2 id="security-title">Useful for XWiki security and access protection</h2>
186 +
82 82   <p>
83 - After username and password verification, users complete an additional step before accessing XWiki.
84 - The flow can require one verification method or both app and email codes.
188 + Many organizations use XWiki to store internal documentation, procedures, operational
189 + knowledge and business-critical information. Adding an additional authentication factor helps
190 + reduce the risk of account compromise when a password is exposed or reused.
85 85   </p>
192 +
193 + <p>
194 + The extension is especially useful for protecting administrator accounts, remote users,
195 + private knowledge bases and customer or partner portals.
196 + </p>
86 86   </article>
87 87  
88 - <article class="product-feature">
89 - <div class="card-heading">
90 - <div class="feature-icon">
91 - <i class="fa fa-mobile" aria-hidden="true"></i>
199 + <aside class="product-info-card" aria-labelledby="use-cases-title">
200 + <h3 id="use-cases-title">Typical use cases</h3>
201 + <ul>
202 + <li>Administrator account protection</li>
203 + <li>Internal knowledge base security</li>
204 + <li>Private documentation platforms</li>
205 + <li>Remote user access protection</li>
206 + <li>Customer or partner portals</li>
207 + <li>Security review, MFA rollout and compliance readiness</li>
208 + </ul>
209 + </aside>
210 + </div>
211 + </div>
212 +</section>
213 +
214 +<section aria-labelledby="admin-experience-title">
215 + <div class="container">
216 + <h2 id="admin-experience-title">Administrator configuration and monitoring</h2>
217 +
218 + <p class="section-intro">
219 + Administrators can configure the policy, define recovery options and monitor adoption
220 + from the XWiki Administration section.
221 + </p>
222 +
223 + <div class="product-feature-grid">
224 + #foreach ($entry in $adminExperienceItems)
225 + <article class="product-feature">
226 + <div class="card-heading">
227 + <div class="feature-icon">
228 + <i class="fa fa-$entry.icon" aria-hidden="true"></i>
229 + </div>
230 + <h3>$entry.title</h3>
92 92   </div>
93 - <h3>Authenticator app codes</h3>
94 - </div>
95 95  
233 + <p>$entry.content</p>
234 + </article>
235 + #end
236 + </div>
237 +
238 +{{/html}}
239 +
240 +{{gallery}}
241 +[[image:mfa-admin-configuration.png]]
242 +[[image:mfa-admin-overview.png]]
243 +[[image:mfa-admin-full.png]]
244 +{{/gallery}}
245 +
246 +{{html clean="false"}}
247 +
248 + <p class="product-gallery-caption">
249 + Administration screens for configuring the policy and reviewing adoption across users.
250 + </p>
251 + </div>
252 +</section>
253 +
254 +<section class="product-section-muted" aria-labelledby="user-experience-title">
255 + <div class="container">
256 + <h2 id="user-experience-title">User setup and login verification</h2>
257 +
258 + <p class="section-intro">
259 + Users can configure the authenticator app from their profile or during the enforced setup flow,
260 + then verify future logins with a generated code.
261 + </p>
262 +
263 + <div class="product-feature-grid">
264 + #foreach ($entry in $userExperienceItems)
265 + <article class="product-feature">
266 + <div class="card-heading">
267 + <div class="feature-icon">
268 + <i class="fa fa-$entry.icon" aria-hidden="true"></i>
269 + </div>
270 + <h3>$entry.title</h3>
271 + </div>
272 +
273 + <p>$entry.content</p>
274 + </article>
275 + #end
276 + </div>
277 +
278 +{{/html}}
279 +
280 +{{gallery}}
281 +[[image:mfa-user-setup-qr.png]]
282 +[[image:mfa-login-verification-setup.png]]
283 +[[image:mfa-login-verification-code.png]]
284 +{{/gallery}}
285 +
286 +{{html clean="false"}}
287 +
288 + <p class="product-gallery-caption">
289 + User setup, enforced configuration and login verification screens.
290 + </p>
291 + </div>
292 +</section>
293 +
294 +<section aria-labelledby="self-service-title">
295 + <div class="container">
296 + <h2 id="self-service-title">Recovery codes and trusted devices</h2>
297 +
298 + <p class="section-intro">
299 + Recovery codes and trusted devices help balance stronger access protection with a smoother user experience.
300 + </p>
301 +
302 + <div class="product-feature-grid">
303 + #foreach ($entry in $selfServiceItems)
304 + <article class="product-feature">
305 + <div class="card-heading">
306 + <div class="feature-icon">
307 + <i class="fa fa-$entry.icon" aria-hidden="true"></i>
308 + </div>
309 + <h3>$entry.title</h3>
310 + </div>
311 +
312 + <p>$entry.content</p>
313 + </article>
314 + #end
315 + </div>
316 +
317 +{{/html}}
318 +
319 +{{gallery}}
320 +[[image:mfa-user-profile-overview.png]]
321 +[[image:mfa-recovery-codes-not-generated.png]]
322 +[[image:mfa-recovery-codes-generated.png]]
323 +[[image:mfa-trusted-devices.png]]
324 +[[image:mfa-user-profile-full.png]]
325 +{{/gallery}}
326 +
327 +{{html clean="false"}}
328 +
329 + <p class="product-gallery-caption">
330 + User profile screens for recovery codes, trusted devices and self-service management.
331 + </p>
332 + </div>
333 +</section>
334 +
335 +<section class="product-section-muted" aria-labelledby="admin-support-title">
336 + <div class="container">
337 + <h2 id="admin-support-title">Administrator support and user recovery</h2>
338 +
339 + <p class="section-intro">
340 + Administrators can help users recover from lost devices or restart setup when needed.
341 + </p>
342 +
343 + <div class="product-feature-grid">
344 + #foreach ($entry in $adminSupportItems)
345 + <article class="product-feature">
346 + <div class="card-heading">
347 + <div class="feature-icon">
348 + <i class="fa fa-$entry.icon" aria-hidden="true"></i>
349 + </div>
350 + <h3>$entry.title</h3>
351 + </div>
352 +
353 + <p>$entry.content</p>
354 + </article>
355 + #end
356 + </div>
357 +
358 +{{/html}}
359 +
360 +{{gallery}}
361 +[[image:mfa-admin-user-management.png]]
362 +{{/gallery}}
363 +
364 +{{html clean="false"}}
365 +
366 + <p class="product-gallery-caption">
367 + Administrator view for checking and resetting a user setup.
368 + </p>
369 + </div>
370 +</section>
371 +
372 +<section aria-labelledby="faq-title">
373 + <div class="container">
374 + <h2 id="faq-title">Frequently asked questions</h2>
375 +
376 + <p class="section-intro">
377 + Common questions about how the extension works, how users configure it and how administrators can manage rollout and recovery.
378 + </p>
379 +
380 + <div class="resource-content">
381 + <details class="resource-faq-item">
382 + <summary>Does this extension replace the standard XWiki login?</summary>
96 96   <p>
97 - Users can verify access with TOTP codes generated by authenticator applications on mobile or desktop devices.
384 + No. Users still sign in with their normal XWiki username and password. The extension adds
385 + an additional verification step after the standard login check.
98 98   </p>
99 - </article>
387 + </details>
100 100  
101 - <article class="product-feature">
102 - <div class="card-heading">
103 - <div class="feature-icon">
104 - <i class="fa fa-envelope-o" aria-hidden="true"></i>
105 - </div>
106 - <h3>Email verification codes</h3>
107 - </div>
389 + <details class="resource-faq-item">
390 + <summary>Which verification method is used?</summary>
391 + <p>
392 + Users verify access with time-based codes generated by an authenticator application.
393 + The setup page provides a QR code and a manual setup key.
394 + </p>
395 + </details>
108 108  
397 + <details class="resource-faq-item">
398 + <summary>Can the second verification step be required for all users?</summary>
109 109   <p>
110 - Users can receive one-time verification codes by email when an authenticator app is not available or preferred.
400 + Yes. Administrators can make the verification step optional or required for all users
401 + from the XWiki Administration section.
111 111   </p>
112 - </article>
403 + </details>
404 +
405 + <details class="resource-faq-item">
406 + <summary>What happens if a user loses access to the authenticator app?</summary>
407 + <p>
408 + Recovery codes can provide backup access when enabled. Administrators can also reset
409 + the user setup so the configuration process can be restarted.
410 + </p>
411 + </details>
412 +
413 + <details class="resource-faq-item">
414 + <summary>Can trusted browsers or devices be disabled?</summary>
415 + <p>
416 + Yes. Administrators can configure how long trusted devices remain valid. Setting the
417 + trusted-device duration to 0 disables this option.
418 + </p>
419 + </details>
420 +
421 + <details class="resource-faq-item">
422 + <summary>Is this only a basic 2FA login-code screen?</summary>
423 + <p>
424 + No. The main login mechanism is two-factor authentication, but the application also includes
425 + features needed for a safer organization-wide rollout: enforcement policy, recovery codes,
426 + trusted devices, user self-service, administrator monitoring and administrator reset actions.
427 + </p>
428 + </details>
429 +
430 + <details class="resource-faq-item">
431 + <summary>Is this enough for compliance on its own?</summary>
432 + <p>
433 + No. This extension provides an important access-protection control, but it should be part
434 + of a broader security and compliance approach that includes permissions, upgrades,
435 + infrastructure, monitoring and operational procedures.
436 + </p>
437 + </details>
113 113   </div>
114 114   </div>
115 115  </section>
116 116  
117 -<section class="product-section-muted" aria-labelledby="security-title">
442 +<section class="product-section-muted" aria-labelledby="rollout-title">
118 118   <div class="container">
119 119   <div class="product-layout">
120 120   <article class="product-summary-card">
121 - <h2 id="security-title">Useful for XWiki security and NIS 2 readiness</h2>
446 + <h2 id="rollout-title">Rollout recommendations</h2>
122 122  
123 123   <p>
124 - Many organizations need multi-factor authentication for enterprise software, including internal
125 - knowledge bases, intranets, documentation platforms and systems containing operational procedures
126 - or sensitive business information.
449 + For a smooth rollout, start with a small administrator or pilot group before requiring
450 + the additional verification step for everyone. This helps validate the configuration,
451 + prepare user communication and reduce support issues.
127 127   </p>
128 128  
129 - <p>
130 - For organizations using XWiki, adding two-factor authentication directly to the standard login flow
131 - can help close a practical access-control gap. It can be useful for administrator accounts, remote users,
132 - private knowledge bases and broader security readiness initiatives such as NIS 2 preparation.
133 - </p>
454 + <ol class="process-list">
455 + #foreach ($entry in $rolloutItems)
456 + <li>
457 + <strong>$entry.title</strong>
458 + $entry.content
459 + </li>
460 + #end
461 + </ol>
462 + </article>
134 134  
135 - <p>
136 - This extension is not a complete compliance solution on its own, but it can provide an important
137 - technical control for protecting access to XWiki.
464 + <aside class="product-info-card" aria-labelledby="planning-title">
465 + <h3 id="planning-title">Useful information before installation</h3>
466 +
467 + <p class="product-card-note">
468 + These details help evaluate compatibility, rollout scope and configuration options.
138 138   </p>
139 - </article>
140 140  
141 - <aside class="product-info-card" aria-labelledby="security-controls-title">
142 - <h3 id="security-controls-title">Useful for</h3>
143 143   <ul>
144 - <li>XWiki 2FA rollout</li>
145 - <li>XWiki MFA adoption</li>
146 - <li>Administrator account protection</li>
147 - <li>Remote user access protection</li>
148 - <li>Private knowledge base security</li>
149 - <li>NIS 2 readiness initiatives</li>
472 + <li>XWiki version</li>
473 + <li>Single wiki or wiki farm with subwikis</li>
474 + <li>Current authentication setup</li>
475 + <li>Optional or required rollout policy</li>
476 + <li>Trusted-device policy</li>
477 + <li>Recovery-code policy</li>
478 + <li>Rollout communication needs</li>
150 150   </ul>
151 151   </aside>
152 152   </div>
... ... @@ -157,11 +157,13 @@
157 157   <div class="container">
158 158   <div class="cta-panel">
159 159   <h2 id="cta-title">Interested in using this extension?</h2>
489 +
160 160   <p>
161 - Send a short message with your XWiki version, authentication setup, and whether you need
162 - authenticator app codes, email verification codes, combined verification, or trusted-device remembering.
491 + Send a short message with your XWiki version, current authentication setup and rollout goal.
163 163   </p>
493 +
164 164   <a class="btn btn-primary" href="$xwiki.getURL('contact.WebHome')">Contact Agnease</a>
495 + <a class="btn btn-secondary" href="$xwiki.getURL('pricing.WebHome')#common-packages">View MFA setup price</a>
165 165   </div>
166 166   </div>
167 167  </section>
2fa-authenticator.png
Author
... ... @@ -1,0 +1,1 @@
1 +XWiki.Admin
Size
... ... @@ -1,0 +1,1 @@
1 +1.1 MB
Content
mfa-admin-configuration.png
Author
... ... @@ -1,0 +1,1 @@
1 +XWiki.Admin
Size
... ... @@ -1,0 +1,1 @@
1 +125.3 KB
Content
mfa-admin-full.png
Author
... ... @@ -1,0 +1,1 @@
1 +XWiki.Admin
Size
... ... @@ -1,0 +1,1 @@
1 +184.3 KB
Content
mfa-admin-overview.png
Author
... ... @@ -1,0 +1,1 @@
1 +XWiki.Admin
Size
... ... @@ -1,0 +1,1 @@
1 +64.7 KB
Content
mfa-admin-user-management.png
Author
... ... @@ -1,0 +1,1 @@
1 +XWiki.Admin
Size
... ... @@ -1,0 +1,1 @@
1 +90.8 KB
Content
mfa-login-verification-code.png
Author
... ... @@ -1,0 +1,1 @@
1 +XWiki.Admin
Size
... ... @@ -1,0 +1,1 @@
1 +23.6 KB
Content
mfa-login-verification-setup.png
Author
... ... @@ -1,0 +1,1 @@
1 +XWiki.Admin
Size
... ... @@ -1,0 +1,1 @@
1 +115.9 KB
Content
mfa-recovery-codes-generated.png
Author
... ... @@ -1,0 +1,1 @@
1 +XWiki.Admin
Size
... ... @@ -1,0 +1,1 @@
1 +38.5 KB
Content
mfa-recovery-codes-not-generated.png
Author
... ... @@ -1,0 +1,1 @@
1 +XWiki.Admin
Size
... ... @@ -1,0 +1,1 @@
1 +27.0 KB
Content
mfa-trusted-devices.png
Author
... ... @@ -1,0 +1,1 @@
1 +XWiki.Admin
Size
... ... @@ -1,0 +1,1 @@
1 +59.1 KB
Content
mfa-user-profile-full.png
Author
... ... @@ -1,0 +1,1 @@
1 +XWiki.Admin
Size
... ... @@ -1,0 +1,1 @@
1 +197.5 KB
Content
mfa-user-profile-overview.png
Author
... ... @@ -1,0 +1,1 @@
1 +XWiki.Admin
Size
... ... @@ -1,0 +1,1 @@
1 +193.4 KB
Content
mfa-user-setup-qr.png
Author
... ... @@ -1,0 +1,1 @@
1 +XWiki.Admin
Size
... ... @@ -1,0 +1,1 @@
1 +176.6 KB
Content