---
title: MFA Configurations for VPN Services
slug: kronpam-reference-guide-3-5-0/mfa-configurations-for-vpn-services
description: Learn how Kron PAM MFA can serve as a third-party MFA server, offering primary and secondary authentication options for applications, devices, VPNs, and more. Discover the step-by-step process of activating each feature, including defining user groups and
docTags: 
createdAt: 2022-07-31T18:23:34.000Z
---

Kron PAM MFA can be used as a 3rd party MFA server for all applications, devices, VPNs, etc. that support RADIUS authentication. Two options are available for MFA server support:

1. Both the first authentication (with username and password) and the secondary authentication (with OTP) are provided via Kron PAM. To activate this feature:
   •	Define the VPN device according to the TACACS Access Manager configuration.
   •	Enable MFA on the User Group (Navigate t&#x6F;**&#x20;Administration** >**&#x20;MFA**> **User Group Management**)
2. Only a second authentication with OTP is provided via Kron PAM. To activate this feature:
   •	Define the VPN device and the Device Group Realm with the related users in Kron PAM (See [User Group Creation](docId:0PFGx1fLkALdk66bckpWJ) and [Device Management](docId\:taoj_F-rCmBoLEzYvCI_X)  sections.)
   •	Define the element type property in the VPN Device element type section:
3. Navigate to **Device&#x20;**>**&#x20;Element Type**.
4. Click the **Options** button of the desired element type and select **Show Properties**.
5. Set the **radius.auth.only.token.enabled** property value as **true**.

![](https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/Zum_-bVpyQJzSZDAWxhDU_image.png "Only Second Authentication with OTP")

