---
title: Using MFA for TACACS+ Manager
slug: kronpam-reference-guide-3-5-0/using-mfa-for-tacacs-manager
description: Learn how to activate multi-factor authentication (MFA) for the TACACS+ Manager with this comprehensive guide. Follow the step-by-step instructions, including prerequisites such as acquiring the QR code and installing the Kron PAM mobile app. Enable MFA f
docTags: 
createdAt: 2022-07-31T17:57:12.000Z
---

&#x20;MFA can be used with the TACACS+  Manager. To activate MFA for TACACS+  Manager:

1. Pre-requisite: Admin and users have the QR code, installed the Kron PAM mobile app, scanned the QR code with the mobile app, and MFA is enabled for the user group that will be using MFA for TACACS+ connections. (See sections [Sending the MFA QR Code to Users](docId:2v1tFoapuzNwZujrstWYb), [Creating a Connection Between Kron PAM and the Kron PAM Mobile Application](docId\:wY8kwWqCiiU13Ej1aqNOp), [Enabling Multi-Factor Authentication (MFA)](docId\:HwPgvOmLUkYcBBXxmaigm)&#x20;
2. Connect to **Kron PAM CLI** from the SSH client as a Kron PAM admin user.
3. Stop the TACACS+  function with the command below (do not close the SSH session)
   **systemctl stop pam-tacacs**
4. Log in to the **Kron PAM Web GUI**.
5. Navigate t&#x6F;**&#x20;Administration** > **TACACS Management**.
6. Click the **Options** button, and delete the configuration.

![](https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/55bbpQLNvp2QYQXKFG9V2_image.png "Delete TACACS Management Configuration")

- In the SSH session, edit the **kron\_tacacs.conf&#x20;**&#x66;ile with the command:
  **vi /u01/kron/etc/kron\_tacacs.conf**
  Check the configuration file to see if the parameter below is already configured in it. If not, add the lines below. If there is a hash (#) sign in front of the parameters, delete the hash (#) sign to activate the parameter. If the parameter value is “false”, change it to “true”. To type or add anything in the vi editor, first press the Insert button on the keyboard, then type in the necessary line. Press Esc to exit typing mode. To save the file press Esc, then colon (:), type in **wq!** and press Enter. If you do not want to save the changes to the file, press Esc, then colon (:), then type in **q!** and press Enter.
  The <font color="#eb144c">red text</font> below may need to be changed for Kron PAM installation. If the default values are acceptable for the installation, the red text does not need to be added at all.
  otp \{
  enabled = 1;
  host =<font color="#eb144c"> OTP endpoint webserver ip</font>;
  port =<font color="#eb144c"> OTP endpoint webserver port, default value: 80</font>;
  cache\_interval = 300;
  num\_digits = 6;
  ssl = <font color="#eb144c">1 if the OTP endpoint webserver is working on HTTPS, default value: 0</font>;
  path\_status = <font color="#eb144c">path of the otpStatus service, default value: /twofactorauth-ui/rest/tfa/otpStatus;</font>
  path\_valid = <font color="#eb144c">path of the otpValid service, default value: /twofactorauth-ui/rest/tfa/otpValid</font>;
  }
- Restart the TACACS+ function
  **systemctl restart pam-tacacs**

