Authentik - Implementing 2FA/MFA (TOTP & Duo Push)

Поділитися
Вставка
  • Опубліковано 22 лис 2024

КОМЕНТАРІ • 87

  • @cooptonian
    @cooptonian  2 роки тому +8

    **UPDATE** as of version 2022.9.0 of Authentik, Duo Push MFA NOW automatically registers new users' Duo devices into Authentik!
    The portion of this video where a new user enrollment first scans the QR code with the Duo app, visibly does nothing, and you have to close the QR code tab not only works and logs the user in now...but also the user's Duo Push device now registers in Authentik without having to use the Authentik API browser to manually register your users...

    • @PhillPriceUK
      @PhillPriceUK 2 роки тому

      I wish I could do this but when getting the user to choose Settings > MFA > Enroll > Duo I get an invalid stage error in the logs :(

    • @cooptonian
      @cooptonian  2 роки тому +3

      This is when you try to add Duo to an existing user after the fact correct? Does the stage work correctly with new user enrollment at least? If not, I'd start at fixing that first... I just tested mine with a test user that has TOTP already by going to the user's settings > MFA Devices > Enroll > Duo Authenticator and scanning the QR code. Now this test user can choose either TOTP or Duo at login...for further help, post in the discord with maybe your log (redacted) so others can chime in...

    • @michaelmurney3577
      @michaelmurney3577 8 місяців тому

      thanks for this update, I have finally got the Duo Push working.

  • @jamesnb
    @jamesnb 11 місяців тому +2

    Thank you very much for your series tutorial on Authentik. Using 2023.10.5, it gets much easier to enroll Duo now. Create username in authentik, then in Duo account. Then go to the Stage and select Duo, there should be a button to import user.

    • @ungheanupetrut5092
      @ungheanupetrut5092 8 місяців тому +1

      And you do not need to search for API and all the stuff? Do you have any documentation to see exactly how can I add duo with 2024 authentik version ?

  • @ungheanupetrut5092
    @ungheanupetrut5092 8 місяців тому

    Thanks for the amazing series. Can you please do an updated version for the duo account? Becase this is not actual with the lattest version of authentik and lattest changes on duo security. Thanks

  • @raphaelkrupinski7572
    @raphaelkrupinski7572 Рік тому +1

    Thanks for the video!
    Is there a way to make TOTP required for users with a certain role, like admin?
    Also, I'm missing in your instructions kinda intermediary description of what are you intending to do. For example, say you're setting up enrollment and then you go straight to clicking the interface. If you first say we need such-n-such flows with such-n-such steps, it would be easier to follow, bacause then when you're clicking thru the interface, we'd already know what you're intending to do there.
    Thanks again!

    • @cooptonian
      @cooptonian  Рік тому

      You're welcome. You can write a policy that checks the role of a user and if the policy check is true, proceed to MFA (negate the result if needed). And I'll keep that feedback in mind if I make another authentik video.

  • @zero4webb
    @zero4webb 2 роки тому +1

    Thank you, thank you, thank you! This was very informative.

    • @cooptonian
      @cooptonian  2 роки тому

      You are welcome! Glad it was helpful!

  • @ItsDevOps
    @ItsDevOps Рік тому

    We are implementing MFA via Active Directory which we want to include all our apps and have integration with the Microsoft Authenticator app.

  • @johnackelley
    @johnackelley 9 місяців тому

    Thanks a bunch for this guide. I used it and everything works great. I tried adding it to source authentication as well, but it doesn't seem to work. It prompts for the MFA code, but if you navigate back and then forward again, it bypasses the code.

    • @cooptonian
      @cooptonian  8 місяців тому

      ...as in it bypasses prompting you again or bypass as in allows straight login? May need to bring it up with the dev in discord or their github. Also, for the policy try the option to 'Evaluate when stage is run' if not already set.

    • @johnackelley
      @johnackelley 8 місяців тому

      @@cooptonian so if I login with Google OAuth, it will prompt me for my TOTP code, but if I navigate back to the OAuth without entering the TOTP code and redo the OAuth, it will send me straight in without prompting me for the TOTP code.
      I'll put an issue in on GitHub.

  • @Kaesebrot
    @Kaesebrot 7 місяців тому

    Hi, thank you so much for your videos on Authentik, they've been very helpful. How would you go about implementing MFA recovery keys?

    • @cooptonian
      @cooptonian  7 місяців тому

      You're welcome, glad they've been helpful. The MFA recovery keys is the static tokens option, so if you enabled that you will get a list of tokens/codes (to keep somewhere safe) and so at the MFA prompt, choose static tokens and enter any of those codes if MFA device is ever lost or whatever.

  • @zyadon7964
    @zyadon7964 2 роки тому +3

    Your videos are great and allow me to move away from authelia. I'm currently struggling with using Authentik as LDAP. A video on that would be helpful when you have the time. I've created the provider, application, and outpost. The outpost creation automatically created a seperate docker container which looks like it's running fine. Nextcloud isn't connecting correctly though, and I suspect I did something wrong in Authentik.

    • @cooptonian
      @cooptonian  2 роки тому +1

      That's awesome, glad they are of help...for LDAP, have you tried checking the discord? A user in there by the name of Hooray4Rob seems to have it setup and working for his purpose... In any case, I may eventually do an LDAP video but there's not ETA on that as I don't personally use it...

  • @fairlightje
    @fairlightje Рік тому +1

    When i try to setup a duo push device it gives me this error: "No variant of ChallengeTypes exists with 'component=undefined'"

    • @fairlightje
      @fairlightje Рік тому +1

      Ok, seems like you get this error if you the username is already in use within DUO

  • @robhedrick9162
    @robhedrick9162 2 роки тому +1

    thanks! Wow, the Duo setup is tedious. I think I would just set this up for my user. I've got everthing else setup (and working) using docker-compose. I am kicking myself for trying it there first... I recently got my kubernetes cluster up and fully functioning. I know they have a helm chart to install Authentik, but there is not easy way to backup and move it over. I'll probably have to do a fresh install via helm and re-configure.
    Thanks again for this!

    • @cooptonian
      @cooptonian  2 роки тому

      You're welcome...yeah I thought it was tedious also; I wish it was as simple as the TOTP setup but the dev documented it had to do with how the Duo API works.

    • @robhedrick9162
      @robhedrick9162 2 роки тому

      @@cooptonian is there an easy way to change the label for the auth options? The users I would have using it (friends/family) don't understand things like TOTP :) ... like just making it say Authenticator App

    • @cooptonian
      @cooptonian  2 роки тому +1

      Yeah, just change the Name of the stage. For instance, mine says default-authenticator-totp-setup | TOTP Authenticator Setup Stage, so the default-authenticator-totp-setup part can be changed to whatever you want it to say, the 2nd part can't since it literally is the stage type (you know from when you click Create when creating a new stage)

    • @robhedrick9162
      @robhedrick9162 2 роки тому

      @@cooptonian Awesome... did you ever figure out how to change the button txt on the recovery email page from "Log in" to something that makes more sense?

    • @cooptonian
      @cooptonian  2 роки тому

      No, however, if we know which HTML file it is within the docker container, it can simply be edited to say whatever (as long as it isn't a linked file where it is shared with, for instance, the main login page because then that would also change). You can see for yourself by inspecting the button in the browser and find the string "Log in" and change that to whatever and it will reflect in your current browser session.
      ...submitted a Github issue regarding the text in the button for dev to hopefully address in the next release: github.com/goauthentik/authentik/issues/3589

  • @-joggs-
    @-joggs- 2 роки тому +1

    How do you disable enrollment? There is a risk when adding logging in with oauth, for example google, as you always can login with a valid google account and then just create a username and you are in. Cannot see anywhere where you can disable user creation

    • @cooptonian
      @cooptonian  2 роки тому +1

      ...first you'd want to add a deny stage at top of your enrollment flow. Then if you want to remove it from the main page, update your identification stage under flow settings and be sure to remove the enrollment flow...

  • @furryrefuge
    @furryrefuge 8 місяців тому

    i love your videos! a video about using SMS 2FA using Twilio would be amazing!

  • @EvilBlood-nf5tp
    @EvilBlood-nf5tp 8 місяців тому

    Thanks for your great videos. I have a question is it possible to set this up so that if the user has configured more than one MFA (for example TOTP and DUO) that the user is asked for the password of which MFA he wants to use?

    • @cooptonian
      @cooptonian  8 місяців тому

      ...not sure I understand; if you have multiple MFA set up, it should prompt you with a screen of MFA choices that you've registered...

    • @EvilBlood-nf5tp
      @EvilBlood-nf5tp 8 місяців тому

      @@cooptonian I have activated WebAuthn Device, TOTP Authenticator and Static Token in my test account. After I have entered my user and password, I am asked directly for the TOTP. I have selected all devices for default-authentication-mfa-validation.
      Update: I have just seen that there is a button underneath labeled: "Return to device picker" if I press it I am logged in directly without using an MFA method.

    • @cooptonian
      @cooptonian  8 місяців тому

      ...that doesn't seem right...if you found a bug, please bring it up with the dev in discord or github issue.

  • @aniwan6620
    @aniwan6620 2 роки тому +1

    Hi, thanks you for your explanation ! Is it possible to force fews group who have to connect with MFA, and maybe one or two who no needs ? For exemple, i would like to admin groups have to connect with mfa like webauth or duo, but i would like to normal user will be connected how he want. Thanks for your help :)

    • @cooptonian
      @cooptonian  2 роки тому +1

      ...I believe you can by using Groups. For more info start up a chat in the discord.

  • @fredzibulski3111
    @fredzibulski3111 Рік тому +1

    I got it work with TOTP awsome thank you for the video.
    I was trying to get it to work with a yubikey but it keeps on saying the entered code is wrong even though it was setup as requested. Any ideas 💡?

    • @cooptonian
      @cooptonian  Рік тому

      ...you're welcome. As for Yubikey, I don't have one so I can't comment on that particular setup; did you ask someone else in the discord that might have a similar setup?

    • @fredzibulski3111
      @fredzibulski3111 Рік тому

      @@cooptonian yes unfortunately did not get an answer yet. Will wait it out then

  • @hoedhoes
    @hoedhoes Рік тому

    Anyway to bind mfa to groups instead? for example I rather have an MFA-Enabled group that I assign to users

    • @cooptonian
      @cooptonian  Рік тому

      ...yeah you can probably do this with an expression policy (kind of the same method as my MFA bypass if on LAN video)

  • @ScottElblein
    @ScottElblein Рік тому

    Hayseuss Christ .... you need a Master's Degree to get this all setup. Their website motto is "Making authentication simple.". I zoned out halfway through over my morning coffee watching this, lol. Think I'll stick with Authelia.

    • @cooptonian
      @cooptonian  Рік тому

      LOL...ha ha, yeah some stuff can be tedious...the Duo part is, relatively, much simpler now (which I believe I either pinned or updated in description)

  • @adtwomey
    @adtwomey 2 роки тому +1

    Nice video man.

  • @PrzemekSkweres
    @PrzemekSkweres 2 роки тому +1

    Hi, is there guide to add TOTP to selfhosted app from Nginx Proxy Manager?

    • @cooptonian
      @cooptonian  2 роки тому

      I am not sure what you mean as this video demonstrates that... Authentik is what serves 2FA/MFA (for your case TOTP). Once confirmed the app loads... So if properly setup, you will be served with TOTP prompt either trying to load the Authentik dashboard or a self-hosted app (if you've set up the app proxy or forward auth). If you haven't setup up your app with the code snippet to use Authentik I highly recommend checking out my application setup video. I hope that makes sense...

    • @PrzemekSkweres
      @PrzemekSkweres 2 роки тому

      Hi, thanks for fast answer. Please forgive me but I'm newbie with that and that don't make sense for me. I have emby server with Nginx Proxy Manager exposed on web and I don't want users who login to Emby knows my password for Authentik. I want to add TOTP authorisation for Emby.

    • @cooptonian
      @cooptonian  2 роки тому

      I've also messaged you in the discord chat

  • @jamesnb
    @jamesnb 11 місяців тому

    I found maybe a bug: If I select both authentication methods TOTP and DUO, and I manually add a user, set the password. The user that I manually created, once login, will be presented with a blank windows. Two authentication options are still there (move the mouse over it will change to a hand icon) but was not displayed properly. This happens to Authentik version 2023.10.5... Any idea?

    • @cooptonian
      @cooptonian  11 місяців тому

      No, I would recommend trying in an incognito window OR better yet a different browser to make sure it isn't a rendering issue...

  • @gieljanwille
    @gieljanwille Рік тому

    Hi Cooptonian, your guides are great! I'm having trouble setting up a YubiKey authenticator. Maybe it's an idea to make a video of this too :)
    Thanks for the great work!

    • @cooptonian
      @cooptonian  Рік тому

      Thanks, I appreciate it! I am not sure what trouble you're having...if the YubiKey option isn't showing up I'd say try a different browser (if the issue is similar to what some have experienced with WebAuthn not working as expected on Firefox vs Chrome). I don't have a YubiKey...but if I did, I'd definitely look into it... Also, you might want to join and ask in the discord if you haven't already.

  • @monish05m
    @monish05m Рік тому

    hey I setup TFA like this and it works, but I want to change from google authentication to authy, the login page asks my username and password and then asks for tfa, but no option to regenerate the tfa qr? how do I switch TFA ?

    • @cooptonian
      @cooptonian  Рік тому

      ...you will have to login as the user, then go into the user settings and enroll another 2FA/MFA method...

  • @bbrendon
    @bbrendon 2 роки тому +2

    I only see "Partner Auth API" in Duo. There isn't a "Auth API"

    • @cooptonian
      @cooptonian  2 роки тому

      Yes, Duo has changed/updated...it is now labeled "Partner Auth API"

  • @emf9
    @emf9 6 місяців тому

    If I follow the instructions for totp how exactly would I go about adding duo to an existing user that has totp enabled?

    • @cooptonian
      @cooptonian  6 місяців тому +1

      Duo is much easier to implement now vs the video I release. In any case, to add another MFA method, that user has to log into their account, goto settings, MFA devices and enroll a new method...

    • @emf9
      @emf9 6 місяців тому

      Thanks! Random, but I'm mostly just curious, is it possible to do a flow like cloudflared email based otp? My thought is to do an identification stage, then an email stage to clock the link to login.... I tried messing with it, but couldn't get it to work. It's academic just to play with stages and flows

  • @marcinchos
    @marcinchos 2 роки тому

    Great job!

  • @pewter77
    @pewter77 2 роки тому

    The choices tab for the authenticators at 10:18 is kinda ugly, is there a way to make this better?

    • @cooptonian
      @cooptonian  2 роки тому

      ...you can change what the choices say by changing the names (the hyphenated name), however, the description underneath these are baked in as device classes...so those may need to be edited from source.

  • @ataliqueshaikh8611
    @ataliqueshaikh8611 10 місяців тому

    How can I set the 2FA for an existing user, for example akadmin ?

    • @cooptonian
      @cooptonian  10 місяців тому

      log in as admin, Directory > Users, Impersonate the user you want, Settings, MFA Devices, Enroll...

  • @WasimAhmad-q9k8l
    @WasimAhmad-q9k8l Рік тому

    thanks for creating such a content, how the tenants work, i got confused ?

    • @cooptonian
      @cooptonian  Рік тому +1

      ...you use the tentants if you have multiple domains where you want your configurations to behave differently based on a particular domain that is accessed (goauthentik.io/docs/tenants).

    • @WasimAhmad-q9k8l
      @WasimAhmad-q9k8l Рік тому

      @@cooptonian sounds good, thanks.
      is there any way where we can have separate providers, apps, users and groups in individual tenant?

    • @cooptonian
      @cooptonian  Рік тому +1

      ...not exactly sure what you mean. In a single tenant you can have various/different providers (proxy [simple, forward-auth, forward-auth domain level], ldap, oauth...etc), apps are up to you as to what you want accessed, users...have as many as you want but can't be existing already/conflicting, and have whatever groups you want (admins, users, restricted, finance, helpdesk...etc.)

    • @WasimAhmad-q9k8l
      @WasimAhmad-q9k8l Рік тому

      @@cooptonian sorry for the confusion,
      Actually, I mean, can we have providers or apps in a tenant?

    • @cooptonian
      @cooptonian  Рік тому

      yes...
      access from public internet > hits your reverse proxy OR authentik simple proxy > where authentik's outpost directs to > provider auth method > to app...
      Providers and applications have 1:1 relationship (so each app needs a provider), all these relationships can use the same outpost. If it is a fairly simple environment, all can use the embedded outpost.

  • @PhillPriceUK
    @PhillPriceUK 2 роки тому

    Duo Push, I’m in.

  • @luisgagocasas
    @luisgagocasas 2 роки тому

    thanks!

  • @fulesmackofule
    @fulesmackofule 10 місяців тому

    Can Authentik support a free provider of push notifications? Duo is not for free.

    • @cooptonian
      @cooptonian  10 місяців тому

      yes, webauthn/passkey...you attempt to login and you will prompted to verify biometrics on your mobile device...

    • @fulesmackofule
      @fulesmackofule 10 місяців тому +1

      @@cooptonianThank you for replying!

  • @casadream29
    @casadream29 Рік тому +1

    Hello /api/v3/stages/all do not exist ^^ on 2023.3.1 😞 But tank you for videos, this is juste incredible I like !!!

    • @casadream29
      @casadream29 Рік тому

      propably the api as changed. Google 2FA work fine, but Duo (I have with Authelia) is hard on new version of Authentik.

    • @cooptonian
      @cooptonian  Рік тому +1

      Hey thanks! Yeah my pinned comment says the newer authenik versions no longer need the part of the video where it uses the API browser stuff...so should be quicker/easier.

    • @casadream29
      @casadream29 Рік тому +1

      @@cooptonian Thanks, work great ! Many thanks for you videos ! Have a nice day.