---
title: Using MFA for Radius
slug: kronpam-reference-guide-3-5-0/using-mfa-for-radius
description: Learn how to enable Multi-Factor Authentication (MFA) for Radius Authentication using the Kron PAM mobile app with this step-by-step guide. From establishing an SSH connection to editing the sc_radiusd.conf file, ensure a secure setup. Discover how to mod
docTags: 
createdAt: 2022-12-02T09:29:57.000Z
---

MFA can also be used with the Radius Authentication. To activate MFA for Radius:

**Pre-requisite:** Admin and users have the QR code, installed the Kron PAM mobile app, scanned the QR code with the mobile app, and MFA is enabled for the user group that will be using MFA for Radius connections.&#x20;

1. Establish an SSH connection to Kron PAM as the pamuser
2. Edit the **sc\_radiusd.conf** file with the command below:
   vi /etc/raddb/sc\_radiusd.conf

Check the configuration file to see if the parameter below is already configured. If not, add the lines below. If there is a hash (# ) sign in front of the parameters, delete the hash ( # ) sign to activate the parameter. If the parameter value is false, change it to true. (Default value is true) To type or add anything in the vi editor, first press the Insert button on the keyboard, then type in the necessary line. Press Esc to exit typing mode. To save the file press Esc, then colon (: ), then type in “wq!”, and press enter. If you don’t want to save the changes on the file, press Esc, then colon (: ), then type in “q!”, and press enter.
sc\_otp\_enabled=true

:::hint{type="info"}
When the OTP login screen comes up, the system message can be changed under the sc\_radiusd.conf file. Default message: sc\_otp\_message="Single Connect - Please Enter OTP:"
:::

Service restart is required for the change in the configuration file to take place.
**systemctl restart pam-radius.service**