Version 30.5 by Alex Cotiuga on 2026/07/13 06:57

Show last authors
1 {{velocity}}
2 #set ($discard = $xwiki.ssx.use('PublicWebSite.WebHome'))
3
4 #set ($mainCapabilityItems = [{
5 'title': 'Second verification step',
6 'icon': 'key',
7 'content': 'Add an additional verification screen after the normal XWiki username and password login.'
8 },{
9 'title': 'Authenticator app codes',
10 'icon': 'mobile',
11 'content': 'Let users verify access with time-based TOTP codes generated by authenticator applications.'
12 },{
13 'title': 'Recovery and trusted devices',
14 'icon': 'shield',
15 'content': 'Provide backup access with recovery codes and reduce repeated prompts on trusted browsers.'
16 }])
17
18 #set ($adminExperienceItems = [{
19 'title': 'Rollout policy',
20 'icon': 'cog',
21 'content': 'Make additional verification optional at first or required for all users from the XWiki Administration section.'
22 },{
23 'title': 'Configuration options',
24 'icon': 'sliders',
25 'content': 'Set the authenticator issuer name, recovery-code count and trusted-device duration.'
26 },{
27 'title': 'Administration overview',
28 'icon': 'table',
29 'content': 'Review adoption with summary indicators and a filterable Live Data table.'
30 }])
31
32 #set ($userExperienceItems = [{
33 'title': 'Self-service setup',
34 'icon': 'qrcode',
35 'content': 'Users configure the second verification step from their profile by scanning a QR code or entering the setup key manually.'
36 },{
37 'title': 'Login verification',
38 'icon': 'sign-in',
39 'content': 'After the normal login, users enter the verification code generated by their authenticator app.'
40 },{
41 'title': 'Trusted browser option',
42 'icon': 'desktop',
43 'content': 'Users can trust the current browser for the configured duration after successful verification.'
44 }])
45
46 #set ($selfServiceItems = [{
47 'title': 'Recovery codes',
48 'icon': 'life-ring',
49 'content': 'Recovery codes provide backup access when a user loses access to the authenticator application.'
50 },{
51 'title': 'Trusted devices',
52 'icon': 'desktop',
53 'content': 'Trusted devices can be reviewed and removed from the user profile.'
54 },{
55 'title': 'Profile management',
56 'icon': 'user',
57 'content': 'Users can review status, generate recovery codes, manage trusted devices and reset their setup.'
58 }])
59
60 #set ($adminSupportItems = [{
61 'title': 'User status',
62 'icon': 'user',
63 'content': 'Administrators can open a user profile and check the verification status for that account.'
64 },{
65 'title': 'Setup reset',
66 'icon': 'refresh',
67 'content': 'Administrators can reset the setup when a user needs to restart the configuration process.'
68 },{
69 'title': 'Controlled recovery',
70 'icon': 'unlock-alt',
71 'content': 'Resetting the setup removes the authenticator configuration, recovery codes and trusted devices for that user.'
72 }])
73
74 #set ($rolloutItems = [{
75 'title': 'Start with a pilot group',
76 'content': 'Test the extension with administrators or a small user group before enabling it widely.'
77 },{
78 'title': 'Define the rollout policy',
79 'content': 'Decide whether additional verification should be optional at first or required for all users.'
80 },{
81 'title': 'Configure recovery options',
82 'content': 'Choose the number of recovery codes and whether trusted devices should be allowed.'
83 },{
84 'title': 'Inform users',
85 'content': 'Explain how users configure the authenticator app, save recovery codes and manage trusted devices.'
86 },{
87 'title': 'Monitor adoption',
88 'content': 'Use the administration overview to identify users who still need to configure protection.'
89 }])
90
91 {{html clean="false"}}
92
93 <section class="hero hero-centered" aria-labelledby="product-title">
94 <div class="container hero-inner">
95 <div class="hero-kicker">
96 <i class="fa fa-lock" aria-hidden="true"></i>
97 XWiki 2FA with MFA rollout support
98 </div>
99
100 <h1 id="product-title">XWiki Two-Factor Authentication</h1>
101
102 <p class="lead">
103 Protect XWiki logins with authenticator app verification, recovery codes,
104 trusted devices and administration controls for a safer rollout.
105 </p>
106
107 <div class="product-card-kicker">
108 <i class="fa fa-tag" aria-hidden="true"></i>
109 Extension from €95/year · Basic setup from €150
110 </div>
111
112 <div class="hero-actions">
113 <a class="btn btn-primary" href="$xwiki.getURL('contact.WebHome')">Ask about this extension</a>
114 <a class="btn btn-secondary" href="$xwiki.getURL('pricing.WebHome')#common-packages">View MFA setup price</a>
115 </div>
116 </div>
117 </section>
118
119 <section aria-labelledby="overview-title">
120 <div class="container">
121 <div class="product-layout">
122 <article class="product-summary-card">
123 <h2 id="overview-title">Two-factor authentication built into XWiki</h2>
124
125 <p>
126 XWiki Two-Factor Authentication adds an additional verification step to the standard
127 XWiki login flow. Users continue to sign in with their normal username and password,
128 then confirm access with a time-based code from an authenticator application.
129 </p>
130
131 <p>
132 The application has evolved beyond a simple login-code screen. It supports global
133 enforcement, recovery codes, trusted devices, user self-service, administrator
134 reset actions and an overview for monitoring adoption.
135 </p>
136 </article>
137
138 <aside class="product-info-card" aria-labelledby="quick-facts-title">
139 <h3 id="quick-facts-title">Quick facts</h3>
140 <ul>
141 <li>Works with the standard XWiki login flow</li>
142 <li>Supports TOTP authenticator applications</li>
143 <li>Can require additional verification for all users</li>
144 <li>Includes one-time recovery codes</li>
145 <li>Can remember trusted browsers or devices</li>
146 <li>Includes user self-service controls</li>
147 <li>Includes an administration overview</li>
148 </ul>
149 </aside>
150 </div>
151 </div>
152 </section>
153
154 <section aria-labelledby="capabilities-title">
155 <div class="container">
156 <h2 id="capabilities-title">Main capabilities</h2>
157
158 <p class="section-intro">
159 A focused set of authentication protection features for stronger XWiki account security
160 without replacing the familiar login experience.
161 </p>
162
163 <div class="product-feature-grid">
164 #foreach ($entry in $mainCapabilityItems)
165 <article class="product-feature">
166 <div class="card-heading">
167 <div class="feature-icon">
168 <i class="fa fa-$entry.icon" aria-hidden="true"></i>
169 </div>
170 <h3>$entry.title</h3>
171 </div>
172
173 <p>$entry.content</p>
174 </article>
175 #end
176 </div>
177 </div>
178 </section>
179
180 <section class="product-section-muted" aria-labelledby="security-title">
181 <div class="container">
182 <div class="product-layout">
183 <article class="product-summary-card">
184 <h2 id="security-title">Useful for XWiki security and access protection</h2>
185
186 <p>
187 Many organizations use XWiki to store internal documentation, procedures, operational
188 knowledge and business-critical information. Adding an additional authentication factor helps
189 reduce the risk of account compromise when a password is exposed or reused.
190 </p>
191
192 <p>
193 The extension is especially useful for protecting administrator accounts, remote users,
194 private knowledge bases and customer or partner portals.
195 </p>
196 </article>
197
198 <aside class="product-info-card" aria-labelledby="use-cases-title">
199 <h3 id="use-cases-title">Typical use cases</h3>
200 <ul>
201 <li>Administrator account protection</li>
202 <li>Internal knowledge base security</li>
203 <li>Private documentation platforms</li>
204 <li>Remote user access protection</li>
205 <li>Customer or partner portals</li>
206 <li>Security review, MFA rollout and compliance readiness</li>
207 </ul>
208 </aside>
209 </div>
210 </div>
211 </section>
212
213 <section aria-labelledby="admin-experience-title">
214 <div class="container">
215 <h2 id="admin-experience-title">Administrator configuration and monitoring</h2>
216
217 <p class="section-intro">
218 Administrators can configure the policy, define recovery options and monitor adoption
219 from the XWiki Administration section.
220 </p>
221
222 <div class="product-feature-grid">
223 #foreach ($entry in $adminExperienceItems)
224 <article class="product-feature">
225 <div class="card-heading">
226 <div class="feature-icon">
227 <i class="fa fa-$entry.icon" aria-hidden="true"></i>
228 </div>
229 <h3>$entry.title</h3>
230 </div>
231
232 <p>$entry.content</p>
233 </article>
234 #end
235 </div>
236
237 {{/html}}
238
239 {{gallery}}
240 [[image:mfa-admin-configuration.png]]
241 [[image:mfa-admin-overview.png]]
242 [[image:mfa-admin-full.png]]
243 {{/gallery}}
244
245 {{html clean="false"}}
246
247 <p class="product-gallery-caption">
248 Administration screens for configuring the policy and reviewing adoption across users.
249 </p>
250 </div>
251 </section>
252
253 <section class="product-section-muted" aria-labelledby="user-experience-title">
254 <div class="container">
255 <h2 id="user-experience-title">User setup and login verification</h2>
256
257 <p class="section-intro">
258 Users can configure the authenticator app from their profile or during the enforced setup flow,
259 then verify future logins with a generated code.
260 </p>
261
262 <div class="product-feature-grid">
263 #foreach ($entry in $userExperienceItems)
264 <article class="product-feature">
265 <div class="card-heading">
266 <div class="feature-icon">
267 <i class="fa fa-$entry.icon" aria-hidden="true"></i>
268 </div>
269 <h3>$entry.title</h3>
270 </div>
271
272 <p>$entry.content</p>
273 </article>
274 #end
275 </div>
276
277 {{/html}}
278
279 {{gallery}}
280 [[image:mfa-user-setup-qr.png]]
281 [[image:mfa-login-verification-setup.png]]
282 [[image:mfa-login-verification-code.png]]
283 {{/gallery}}
284
285 {{html clean="false"}}
286
287 <p class="product-gallery-caption">
288 User setup, enforced configuration and login verification screens.
289 </p>
290 </div>
291 </section>
292
293 <section aria-labelledby="self-service-title">
294 <div class="container">
295 <h2 id="self-service-title">Recovery codes and trusted devices</h2>
296
297 <p class="section-intro">
298 Recovery codes and trusted devices help balance stronger access protection with a smoother user experience.
299 </p>
300
301 <div class="product-feature-grid">
302 #foreach ($entry in $selfServiceItems)
303 <article class="product-feature">
304 <div class="card-heading">
305 <div class="feature-icon">
306 <i class="fa fa-$entry.icon" aria-hidden="true"></i>
307 </div>
308 <h3>$entry.title</h3>
309 </div>
310
311 <p>$entry.content</p>
312 </article>
313 #end
314 </div>
315
316 {{/html}}
317
318 {{gallery}}
319 [[image:mfa-user-profile-overview.png]]
320 [[image:mfa-recovery-codes-not-generated.png]]
321 [[image:mfa-recovery-codes-generated.png]]
322 [[image:mfa-trusted-devices.png]]
323 [[image:mfa-user-profile-full.png]]
324 {{/gallery}}
325
326 {{html clean="false"}}
327
328 <p class="product-gallery-caption">
329 User profile screens for recovery codes, trusted devices and self-service management.
330 </p>
331 </div>
332 </section>
333
334 <section class="product-section-muted" aria-labelledby="admin-support-title">
335 <div class="container">
336 <h2 id="admin-support-title">Administrator support and user recovery</h2>
337
338 <p class="section-intro">
339 Administrators can help users recover from lost devices or restart setup when needed.
340 </p>
341
342 <div class="product-feature-grid">
343 #foreach ($entry in $adminSupportItems)
344 <article class="product-feature">
345 <div class="card-heading">
346 <div class="feature-icon">
347 <i class="fa fa-$entry.icon" aria-hidden="true"></i>
348 </div>
349 <h3>$entry.title</h3>
350 </div>
351
352 <p>$entry.content</p>
353 </article>
354 #end
355 </div>
356
357 {{/html}}
358
359 {{gallery}}
360 [[image:mfa-admin-user-management.png]]
361 {{/gallery}}
362
363 {{html clean="false"}}
364
365 <p class="product-gallery-caption">
366 Administrator view for checking and resetting a user setup.
367 </p>
368 </div>
369 </section>
370
371 <section aria-labelledby="faq-title">
372 <div class="container">
373 <h2 id="faq-title">Frequently asked questions</h2>
374
375 <p class="section-intro">
376 Common questions about how the extension works, how users configure it and how administrators can manage rollout and recovery.
377 </p>
378
379 <div class="resource-content">
380 <details class="resource-faq-item">
381 <summary>Does this extension replace the standard XWiki login?</summary>
382 <p>
383 No. Users still sign in with their normal XWiki username and password. The extension adds
384 an additional verification step after the standard login check.
385 </p>
386 </details>
387
388 <details class="resource-faq-item">
389 <summary>Which verification method is used?</summary>
390 <p>
391 Users verify access with time-based codes generated by an authenticator application.
392 The setup page provides a QR code and a manual setup key.
393 </p>
394 </details>
395
396 <details class="resource-faq-item">
397 <summary>Can the second verification step be required for all users?</summary>
398 <p>
399 Yes. Administrators can make the verification step optional or required for all users
400 from the XWiki Administration section.
401 </p>
402 </details>
403
404 <details class="resource-faq-item">
405 <summary>What happens if a user loses access to the authenticator app?</summary>
406 <p>
407 Recovery codes can provide backup access when enabled. Administrators can also reset
408 the user setup so the configuration process can be restarted.
409 </p>
410 </details>
411
412 <details class="resource-faq-item">
413 <summary>Can trusted browsers or devices be disabled?</summary>
414 <p>
415 Yes. Administrators can configure how long trusted devices remain valid. Setting the
416 trusted-device duration to 0 disables this option.
417 </p>
418 </details>
419
420 <details class="resource-faq-item">
421 <summary>Is this only a basic 2FA login-code screen?</summary>
422 <p>
423 No. The main login mechanism is two-factor authentication, but the application also includes
424 features needed for a safer organization-wide rollout: enforcement policy, recovery codes,
425 trusted devices, user self-service, administrator monitoring and administrator reset actions.
426 </p>
427 </details>
428
429 <details class="resource-faq-item">
430 <summary>Is this enough for compliance on its own?</summary>
431 <p>
432 No. This extension provides an important access-protection control, but it should be part
433 of a broader security and compliance approach that includes permissions, upgrades,
434 infrastructure, monitoring and operational procedures.
435 </p>
436 </details>
437 </div>
438 </div>
439 </section>
440
441 <section class="product-section-muted" aria-labelledby="rollout-title">
442 <div class="container">
443 <div class="product-layout">
444 <article class="product-summary-card">
445 <h2 id="rollout-title">Rollout recommendations</h2>
446
447 <p>
448 For a smooth rollout, start with a small administrator or pilot group before requiring
449 the additional verification step for everyone. This helps validate the configuration,
450 prepare user communication and reduce support issues.
451 </p>
452
453 <ol class="process-list">
454 #foreach ($entry in $rolloutItems)
455 <li>
456 <strong>$entry.title</strong>
457 $entry.content
458 </li>
459 #end
460 </ol>
461 </article>
462
463 <aside class="product-info-card" aria-labelledby="planning-title">
464 <h3 id="planning-title">Useful information before installation</h3>
465
466 <p class="product-card-note">
467 These details help evaluate compatibility, rollout scope and configuration options.
468 </p>
469
470 <ul>
471 <li>XWiki version</li>
472 <li>Single wiki or wiki farm with subwikis</li>
473 <li>Current authentication setup</li>
474 <li>Optional or required rollout policy</li>
475 <li>Trusted-device policy</li>
476 <li>Recovery-code policy</li>
477 <li>Rollout communication needs</li>
478 </ul>
479 </aside>
480 </div>
481 </div>
482 </section>
483
484 <section class="cta-section" aria-labelledby="cta-title">
485 <div class="container">
486 <div class="cta-panel">
487 <h2 id="cta-title">Interested in using this extension?</h2>
488
489 <p>
490 Send a short message with your XWiki version, current authentication setup and rollout goal.
491 </p>
492
493 <a class="btn btn-primary" href="$xwiki.getURL('contact.WebHome')">Contact Agnease</a>
494 <a class="btn btn-secondary" href="$xwiki.getURL('pricing.WebHome')#common-packages">View MFA setup price</a>
495 </div>
496 </div>
497 </section>
498
499 {{/html}}
500 {{/velocity}}