---
title: Connecting with the Kron PAM SQL Proxy with MFA
slug: kronpam-reference-guide-3-5-0/connecting-with-the-kron-pam-sql-proxy-with-mfa
docTags: 
createdAt: 2024-07-18T14:26:47.194Z
---

Some configurations must be made to use MFA (Multi-Factor Authentication) when performing SQL Proxy for Oracle database device&#x73;**.&#x20;**&#x50;lease check **2.3 Email Server Configuration&#x20;**&#x62;efore configuring MFA in SQL Proxy.

In the **Multifactor Authentication** and go to **User Group Management**, press the options button for the user group where the SQLPROXY user is (in this example, it is ORACLE UG). Then, press the 'Enable OTP' option on the screen that appears.

![](https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/1_lmNPRw6LrCG7YVvqQkA_image.png)

![](https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/rxAulGXjf2NPlGxNPhtKf_image.png "User Group Management")

After this, navigate to the **Multifactor Authentication page** and go to **the User Token Management** page. Then, press the options button for the user used for the Oracle database (in this case SQLPROXY) and click the **Send Manual Registration Key** button.

![](https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/5LJNOMYq7QYI78e74GYWc_image.png "User Token Management")

![](https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/7TNNXoTTT_cCtFYIMrbbZ_image.png "User Token Management")

In this example, the QR code sent to the email address of the SQLPROXY user needs to be scanned using the KRON PAM mobile application.

::Image[]{src="https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/ZhnH-FodkdymQJz0rgxIb_image.png" size="42" width="368" height="559" position="center" caption="the second one is MFA 6-digit code" showCaption="true"}

Then, two parameters must be entered in the *System Configuration Manager*. By pressing the +Add button, add the following parameters:

- **sql.proxy.2fa.enabled&#x20;**&#x77;ith a value o&#x66;**&#x20;true**
- **sql.proxy.2fa.delimiter&#x20;**&#x77;ith a value o&#x66;**&#x20;#**
  - the delimiter is your choice (in this example, # is used)

![](https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/G9AEti-QPpdMXNEeuoBFx_image.png "System Configuration Manager")

Next, proceed to an SQL Client (in this example, DBeaver is used). The Database Name, Port, and Password are the same as in the SQL Proxy steps.&#x20;

The username is different; here, as an example, enter (SQLPROXY) customer delimiter (#) and the 6-digit code displayed in the KRON PAM application in the Username field. You should be able to connect successfully.

::Image[]{src="https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/k-t_tUZ6oYV4YD7N-aArp_image.png" size="72" width="712" height="631" position="center" caption="MFA 6 digit and Delimiter with Database Username on SQL Proxy" showCaption="true"}

