Applies to Windows Clients only.
Enable one-time passwords
1
Open the Client or Client Group
Log in to the Management Tool as a user with the Client Configuration Management permission. Click Clients, then find the Client or Client group to configure and click its name.
2
Allow one-time passwords
On the Editing Client (or Editing Client Group) page, select the Authentication Options tab, scroll to Two-Factor and Secondary Authentication, and select Allow the use of one-time passwords.
3
Select Approvers
In Users who can approve access, select every user who should be able to approve one-time password requests.
Approvers can process a request either by clicking the link in a notification email (if they have an email address on file), or on the Access Requests page’s Access Requests tab in the Management Tool. A request that isn’t processed within 30 minutes automatically expires by default - adjustable on the System Settings tab of the Configuration page.
4
Optionally enable automatic delivery
To skip Approver review entirely for certain users, select either:
- Automatically send one-time passwords to Active Directory users - requires an email address defined on each such user’s Active Directory account.
- Automatically send one-time passwords to internal users - requires an email address on the internal user’s User Details tab, and the Access to Endpoint via Secondary Auth. permission granted on their Client Access tab.
5
Save
Click Finish.

The Two-Factor and Secondary Authentication section with one-time passwords enabled.
Approve or generate a one-time password
When a user requests access, the request goes to every configured Approver by email and appears on the Access Requests page’s Access Requests tab.- Approve a pending request
- Generate without a request
1
Open Access Requests
Log in to the Management Tool as a listed Approver and click Access Requests.
2
Approve the request
Click Approve next to the relevant request, optionally enter a comment, and click Confirm.
3
Password is emailed
A one-time password is generated and sent automatically to the user’s email address.
Request and log in with a one-time password
This is the end-user flow - what a user sees when they log in to a Client with one-time passwords enabled, as opposed to the admin setup or Approver-initiated generation covered above.1
Log in to Windows normally
Locally or remotely, as usual.
2
Request a one-time password
The Client shows a pop-up asking for a one-time password. Click Request One-Time Password.
3
Provide identifying details
A second pop-up appears, depending on which automatic-delivery options are enabled:
- Neither automatic option enabled - enter an Email address, then click Request.
- Automatically send to Active Directory users enabled - just click Request.
- Automatically send to internal users enabled - enter the internal Management Tool Login and Password, then click Request.
4
Receive the password by email
A confirmation message appears, and the one-time password arrives by email.
5
Enter the password
Back on the first pop-up (now showing the email address automatically), enter the received password.
6
Access is granted or denied
The credentials are validated against the Application Server. If the email and password match, and the password was generated for this user and this Client, access is granted - otherwise the user sees a denial message.
<Windows account> (<email address>) in the Client Sessions list’s User Name column.
A one-time password works only once, only within the Access Request Expiration Time (default 30 minutes), and only for the Client it was requested from. If it expires or needs resending, the user can request again - but no more than once per hour for the same Client.
Related
Secondary user authentication
An alternative, mutually exclusive login-identification method.
Client permissions
Permissions required to configure Clients and approve access.
Windows Clients
Windows Client installation and configuration.
System settings
Change the default request expiration time.