Version 30.6 by Alex Cotiuga on 2026/07/13 06:59

Show last authors
1 {{velocity}}
2 #set ($discard = $xwiki.ssx.use('PublicWebSite.WebHome'))
3
4 #set ($mainCapabilityItems = [{
5 'title': 'Second verification step',
6 'icon': 'key',
7 'content': 'Add an additional verification screen after the normal XWiki username and password login.'
8 },{
9 'title': 'Authenticator app codes',
10 'icon': 'mobile',
11 'content': 'Let users verify access with time-based TOTP codes generated by authenticator applications.'
12 },{
13 'title': 'Recovery and trusted devices',
14 'icon': 'shield',
15 'content': 'Provide backup access with recovery codes and reduce repeated prompts on trusted browsers.'
16 }])
17
18 #set ($adminExperienceItems = [{
19 'title': 'Rollout policy',
20 'icon': 'cog',
21 'content': 'Make additional verification optional at first or required for all users from the XWiki Administration section.'
22 },{
23 'title': 'Configuration options',
24 'icon': 'sliders',
25 'content': 'Set the authenticator issuer name, recovery-code count and trusted-device duration.'
26 },{
27 'title': 'Administration overview',
28 'icon': 'table',
29 'content': 'Review adoption with summary indicators and a filterable Live Data table.'
30 }])
31
32 #set ($userExperienceItems = [{
33 'title': 'Self-service setup',
34 'icon': 'qrcode',
35 'content': 'Users configure the second verification step from their profile by scanning a QR code or entering the setup key manually.'
36 },{
37 'title': 'Login verification',
38 'icon': 'sign-in',
39 'content': 'After the normal login, users enter the verification code generated by their authenticator app.'
40 },{
41 'title': 'Trusted browser option',
42 'icon': 'desktop',
43 'content': 'Users can trust the current browser for the configured duration after successful verification.'
44 }])
45
46 #set ($selfServiceItems = [{
47 'title': 'Recovery codes',
48 'icon': 'life-ring',
49 'content': 'Recovery codes provide backup access when a user loses access to the authenticator application.'
50 },{
51 'title': 'Trusted devices',
52 'icon': 'desktop',
53 'content': 'Trusted devices can be reviewed and removed from the user profile.'
54 },{
55 'title': 'Profile management',
56 'icon': 'user',
57 'content': 'Users can review status, generate recovery codes, manage trusted devices and reset their setup.'
58 }])
59
60 #set ($adminSupportItems = [{
61 'title': 'User status',
62 'icon': 'user',
63 'content': 'Administrators can open a user profile and check the verification status for that account.'
64 },{
65 'title': 'Setup reset',
66 'icon': 'refresh',
67 'content': 'Administrators can reset the setup when a user needs to restart the configuration process.'
68 },{
69 'title': 'Controlled recovery',
70 'icon': 'unlock-alt',
71 'content': 'Resetting the setup removes the authenticator configuration, recovery codes and trusted devices for that user.'
72 }])
73
74 #set ($rolloutItems = [{
75 'title': 'Start with a pilot group',
76 'content': 'Test the extension with administrators or a small user group before enabling it widely.'
77 },{
78 'title': 'Define the rollout policy',
79 'content': 'Decide whether additional verification should be optional at first or required for all users.'
80 },{
81 'title': 'Configure recovery options',
82 'content': 'Choose the number of recovery codes and whether trusted devices should be allowed.'
83 },{
84 'title': 'Inform users',
85 'content': 'Explain how users configure the authenticator app, save recovery codes and manage trusted devices.'
86 },{
87 'title': 'Monitor adoption',
88 'content': 'Use the administration overview to identify users who still need to configure protection.'
89 }])
90
91 {{html clean="false"}}
92
93 <section class="hero hero-centered" aria-labelledby="product-title">
94 <div class="container hero-inner">
95 <div class="hero-kicker">
96 <i class="fa fa-lock" aria-hidden="true"></i>
97 XWiki 2FA with MFA rollout support
98 </div>
99
100 <h1 id="product-title">XWiki Two-Factor Authentication</h1>
101
102 <p class="lead">
103 Protect XWiki logins with authenticator app verification, recovery codes,
104 trusted devices and administration controls for a safer rollout.
105 </p>
106
107 <ul class="benefits">
108 <li><strong>Extension from €95/year</strong></li>
109 <li><strong>Basic setup from €150</strong></li>
110 <li>MFA rollout support available</li>
111 </ul>
112
113 <div class="hero-actions">
114 <a class="btn btn-primary" href="$xwiki.getURL('contact.WebHome')">Ask about this extension</a>
115 <a class="btn btn-secondary" href="$xwiki.getURL('pricing.WebHome')#common-packages">View MFA setup price</a>
116 </div>
117 </div>
118 </section>
119
120 <section aria-labelledby="overview-title">
121 <div class="container">
122 <div class="product-layout">
123 <article class="product-summary-card">
124 <h2 id="overview-title">Two-factor authentication built into XWiki</h2>
125
126 <p>
127 XWiki Two-Factor Authentication adds an additional verification step to the standard
128 XWiki login flow. Users continue to sign in with their normal username and password,
129 then confirm access with a time-based code from an authenticator application.
130 </p>
131
132 <p>
133 The application has evolved beyond a simple login-code screen. It supports global
134 enforcement, recovery codes, trusted devices, user self-service, administrator
135 reset actions and an overview for monitoring adoption.
136 </p>
137 </article>
138
139 <aside class="product-info-card" aria-labelledby="quick-facts-title">
140 <h3 id="quick-facts-title">Quick facts</h3>
141 <ul>
142 <li>Works with the standard XWiki login flow</li>
143 <li>Supports TOTP authenticator applications</li>
144 <li>Can require additional verification for all users</li>
145 <li>Includes one-time recovery codes</li>
146 <li>Can remember trusted browsers or devices</li>
147 <li>Includes user self-service controls</li>
148 <li>Includes an administration overview</li>
149 </ul>
150 </aside>
151 </div>
152 </div>
153 </section>
154
155 <section aria-labelledby="capabilities-title">
156 <div class="container">
157 <h2 id="capabilities-title">Main capabilities</h2>
158
159 <p class="section-intro">
160 A focused set of authentication protection features for stronger XWiki account security
161 without replacing the familiar login experience.
162 </p>
163
164 <div class="product-feature-grid">
165 #foreach ($entry in $mainCapabilityItems)
166 <article class="product-feature">
167 <div class="card-heading">
168 <div class="feature-icon">
169 <i class="fa fa-$entry.icon" aria-hidden="true"></i>
170 </div>
171 <h3>$entry.title</h3>
172 </div>
173
174 <p>$entry.content</p>
175 </article>
176 #end
177 </div>
178 </div>
179 </section>
180
181 <section class="product-section-muted" aria-labelledby="security-title">
182 <div class="container">
183 <div class="product-layout">
184 <article class="product-summary-card">
185 <h2 id="security-title">Useful for XWiki security and access protection</h2>
186
187 <p>
188 Many organizations use XWiki to store internal documentation, procedures, operational
189 knowledge and business-critical information. Adding an additional authentication factor helps
190 reduce the risk of account compromise when a password is exposed or reused.
191 </p>
192
193 <p>
194 The extension is especially useful for protecting administrator accounts, remote users,
195 private knowledge bases and customer or partner portals.
196 </p>
197 </article>
198
199 <aside class="product-info-card" aria-labelledby="use-cases-title">
200 <h3 id="use-cases-title">Typical use cases</h3>
201 <ul>
202 <li>Administrator account protection</li>
203 <li>Internal knowledge base security</li>
204 <li>Private documentation platforms</li>
205 <li>Remote user access protection</li>
206 <li>Customer or partner portals</li>
207 <li>Security review, MFA rollout and compliance readiness</li>
208 </ul>
209 </aside>
210 </div>
211 </div>
212 </section>
213
214 <section aria-labelledby="admin-experience-title">
215 <div class="container">
216 <h2 id="admin-experience-title">Administrator configuration and monitoring</h2>
217
218 <p class="section-intro">
219 Administrators can configure the policy, define recovery options and monitor adoption
220 from the XWiki Administration section.
221 </p>
222
223 <div class="product-feature-grid">
224 #foreach ($entry in $adminExperienceItems)
225 <article class="product-feature">
226 <div class="card-heading">
227 <div class="feature-icon">
228 <i class="fa fa-$entry.icon" aria-hidden="true"></i>
229 </div>
230 <h3>$entry.title</h3>
231 </div>
232
233 <p>$entry.content</p>
234 </article>
235 #end
236 </div>
237
238 {{/html}}
239
240 {{gallery}}
241 [[image:mfa-admin-configuration.png]]
242 [[image:mfa-admin-overview.png]]
243 [[image:mfa-admin-full.png]]
244 {{/gallery}}
245
246 {{html clean="false"}}
247
248 <p class="product-gallery-caption">
249 Administration screens for configuring the policy and reviewing adoption across users.
250 </p>
251 </div>
252 </section>
253
254 <section class="product-section-muted" aria-labelledby="user-experience-title">
255 <div class="container">
256 <h2 id="user-experience-title">User setup and login verification</h2>
257
258 <p class="section-intro">
259 Users can configure the authenticator app from their profile or during the enforced setup flow,
260 then verify future logins with a generated code.
261 </p>
262
263 <div class="product-feature-grid">
264 #foreach ($entry in $userExperienceItems)
265 <article class="product-feature">
266 <div class="card-heading">
267 <div class="feature-icon">
268 <i class="fa fa-$entry.icon" aria-hidden="true"></i>
269 </div>
270 <h3>$entry.title</h3>
271 </div>
272
273 <p>$entry.content</p>
274 </article>
275 #end
276 </div>
277
278 {{/html}}
279
280 {{gallery}}
281 [[image:mfa-user-setup-qr.png]]
282 [[image:mfa-login-verification-setup.png]]
283 [[image:mfa-login-verification-code.png]]
284 {{/gallery}}
285
286 {{html clean="false"}}
287
288 <p class="product-gallery-caption">
289 User setup, enforced configuration and login verification screens.
290 </p>
291 </div>
292 </section>
293
294 <section aria-labelledby="self-service-title">
295 <div class="container">
296 <h2 id="self-service-title">Recovery codes and trusted devices</h2>
297
298 <p class="section-intro">
299 Recovery codes and trusted devices help balance stronger access protection with a smoother user experience.
300 </p>
301
302 <div class="product-feature-grid">
303 #foreach ($entry in $selfServiceItems)
304 <article class="product-feature">
305 <div class="card-heading">
306 <div class="feature-icon">
307 <i class="fa fa-$entry.icon" aria-hidden="true"></i>
308 </div>
309 <h3>$entry.title</h3>
310 </div>
311
312 <p>$entry.content</p>
313 </article>
314 #end
315 </div>
316
317 {{/html}}
318
319 {{gallery}}
320 [[image:mfa-user-profile-overview.png]]
321 [[image:mfa-recovery-codes-not-generated.png]]
322 [[image:mfa-recovery-codes-generated.png]]
323 [[image:mfa-trusted-devices.png]]
324 [[image:mfa-user-profile-full.png]]
325 {{/gallery}}
326
327 {{html clean="false"}}
328
329 <p class="product-gallery-caption">
330 User profile screens for recovery codes, trusted devices and self-service management.
331 </p>
332 </div>
333 </section>
334
335 <section class="product-section-muted" aria-labelledby="admin-support-title">
336 <div class="container">
337 <h2 id="admin-support-title">Administrator support and user recovery</h2>
338
339 <p class="section-intro">
340 Administrators can help users recover from lost devices or restart setup when needed.
341 </p>
342
343 <div class="product-feature-grid">
344 #foreach ($entry in $adminSupportItems)
345 <article class="product-feature">
346 <div class="card-heading">
347 <div class="feature-icon">
348 <i class="fa fa-$entry.icon" aria-hidden="true"></i>
349 </div>
350 <h3>$entry.title</h3>
351 </div>
352
353 <p>$entry.content</p>
354 </article>
355 #end
356 </div>
357
358 {{/html}}
359
360 {{gallery}}
361 [[image:mfa-admin-user-management.png]]
362 {{/gallery}}
363
364 {{html clean="false"}}
365
366 <p class="product-gallery-caption">
367 Administrator view for checking and resetting a user setup.
368 </p>
369 </div>
370 </section>
371
372 <section aria-labelledby="faq-title">
373 <div class="container">
374 <h2 id="faq-title">Frequently asked questions</h2>
375
376 <p class="section-intro">
377 Common questions about how the extension works, how users configure it and how administrators can manage rollout and recovery.
378 </p>
379
380 <div class="resource-content">
381 <details class="resource-faq-item">
382 <summary>Does this extension replace the standard XWiki login?</summary>
383 <p>
384 No. Users still sign in with their normal XWiki username and password. The extension adds
385 an additional verification step after the standard login check.
386 </p>
387 </details>
388
389 <details class="resource-faq-item">
390 <summary>Which verification method is used?</summary>
391 <p>
392 Users verify access with time-based codes generated by an authenticator application.
393 The setup page provides a QR code and a manual setup key.
394 </p>
395 </details>
396
397 <details class="resource-faq-item">
398 <summary>Can the second verification step be required for all users?</summary>
399 <p>
400 Yes. Administrators can make the verification step optional or required for all users
401 from the XWiki Administration section.
402 </p>
403 </details>
404
405 <details class="resource-faq-item">
406 <summary>What happens if a user loses access to the authenticator app?</summary>
407 <p>
408 Recovery codes can provide backup access when enabled. Administrators can also reset
409 the user setup so the configuration process can be restarted.
410 </p>
411 </details>
412
413 <details class="resource-faq-item">
414 <summary>Can trusted browsers or devices be disabled?</summary>
415 <p>
416 Yes. Administrators can configure how long trusted devices remain valid. Setting the
417 trusted-device duration to 0 disables this option.
418 </p>
419 </details>
420
421 <details class="resource-faq-item">
422 <summary>Is this only a basic 2FA login-code screen?</summary>
423 <p>
424 No. The main login mechanism is two-factor authentication, but the application also includes
425 features needed for a safer organization-wide rollout: enforcement policy, recovery codes,
426 trusted devices, user self-service, administrator monitoring and administrator reset actions.
427 </p>
428 </details>
429
430 <details class="resource-faq-item">
431 <summary>Is this enough for compliance on its own?</summary>
432 <p>
433 No. This extension provides an important access-protection control, but it should be part
434 of a broader security and compliance approach that includes permissions, upgrades,
435 infrastructure, monitoring and operational procedures.
436 </p>
437 </details>
438 </div>
439 </div>
440 </section>
441
442 <section class="product-section-muted" aria-labelledby="rollout-title">
443 <div class="container">
444 <div class="product-layout">
445 <article class="product-summary-card">
446 <h2 id="rollout-title">Rollout recommendations</h2>
447
448 <p>
449 For a smooth rollout, start with a small administrator or pilot group before requiring
450 the additional verification step for everyone. This helps validate the configuration,
451 prepare user communication and reduce support issues.
452 </p>
453
454 <ol class="process-list">
455 #foreach ($entry in $rolloutItems)
456 <li>
457 <strong>$entry.title</strong>
458 $entry.content
459 </li>
460 #end
461 </ol>
462 </article>
463
464 <aside class="product-info-card" aria-labelledby="planning-title">
465 <h3 id="planning-title">Useful information before installation</h3>
466
467 <p class="product-card-note">
468 These details help evaluate compatibility, rollout scope and configuration options.
469 </p>
470
471 <ul>
472 <li>XWiki version</li>
473 <li>Single wiki or wiki farm with subwikis</li>
474 <li>Current authentication setup</li>
475 <li>Optional or required rollout policy</li>
476 <li>Trusted-device policy</li>
477 <li>Recovery-code policy</li>
478 <li>Rollout communication needs</li>
479 </ul>
480 </aside>
481 </div>
482 </div>
483 </section>
484
485 <section class="cta-section" aria-labelledby="cta-title">
486 <div class="container">
487 <div class="cta-panel">
488 <h2 id="cta-title">Interested in using this extension?</h2>
489
490 <p>
491 Send a short message with your XWiki version, current authentication setup and rollout goal.
492 </p>
493
494 <a class="btn btn-primary" href="$xwiki.getURL('contact.WebHome')">Contact Agnease</a>
495 <a class="btn btn-secondary" href="$xwiki.getURL('pricing.WebHome')#common-packages">View MFA setup price</a>
496 </div>
497 </div>
498 </section>
499
500 {{/html}}
501 {{/velocity}}