---
title: Using MFA for Mobile Application
slug: kronpam-reference-guide-3-5-0/using-mfa-for-mobile-application
description: Learn how to enable multi-factor authentication (MFA) in Kron PAM's Mobile Application to secure online access. This guide explains the process of installing the Kron PAM Mobile App, registering a token, and enabling MFA for user groups. Discover how the 
docTags: 
createdAt: 2022-07-31T18:06:05.000Z
---

Kron PAM’s built-in MFA can be used as a secondary layer of authentication for logging into the Mobile Application for its online features (Approval Management, Geo-Fencing, and Password Manager).

To enable MFA for Mobile Applications:

:::hint{type="info"}
- Admin and user must install the Kron PAM Mobile App and register a token to receive Offline Tokens with the mobile app. (You get the Offline Tokens from the Offline Token > Add > Register Token menu).
- MFA must be enabled for the user group that will be using MFA for Mobile Application connections. (See sections [Sending the MFA QR Code to Users](docId:2v1tFoapuzNwZujrstWYb), [Creating a Connection Between Kron PAM and the Kron PAM Mobile Application](docId\:wY8kwWqCiiU13Ej1aqNOp), [Enabling Multi-Factor Authentication (MFA)](docId\:HwPgvOmLUkYcBBXxmaigm)&#x20;
:::

1. Navigate to **Administration&#x20;**> **System Configuration Manager**.
2. Set the **mobile.application.otp.enabled&#x20;**&#x70;arameter as true.

After these settings are done and a login operation is started on the mobile application, the application will automatically look for a Registered Token in its Offline Tokens with the name that matches the tfa.otp.issuer parameter. If there is a registered token with another name, then it will prompt the user to change the registered token. The user selects yes and enters a new token on the next page window forward to the token page for entering a new token. If the token is matched the user can log in. Once the current six-digit value of the Offline Token is validated with the server, login will be successful.

::Image[]{src="https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/tyJhcu4_AduDufYabrT8n_image.png" size="40" width="520" height="538" position="center" caption="Token mismatch " showCaption="true"}

::Image[]{src="https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/mn5hp_tI5g1u2_W6xUA3g_image.png" size="42" width="519" height="598" position="center" caption="Token mismatch " showCaption="true"}

::Image[]{src="https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/DhnrZNdcvKqBw2yPsegdE_image.png" size="50" width="522" height="601" position="center" caption="Token mismatch " showCaption="true"}

If there’s no Registered Token in the mobile application and MFA is enabled with the parameter above, registering a token also requires a Multi-Factor Authentication. The system will send a one-time- password (OTP) to the user’s phone number. The user will be asked to enter the OTP on his/her mobile application.

:::hint{type="info"}
The Mobile Application MFA functionality works only with the registered tokens to ensure that the offline tokens are only working in one application at a time.
:::

