Using MFA for RDP Connections
to activate mfa for an rdp connection admin and users have the qr code, installed the kron pam mobile client application , scanned the qr code with the kron pam mobile client application , and otp is enabled for the user group that will be using mfa for rdp connections (see sections sending the mfa qr code to users docid\ keoziwpyp0zorildsdlbg , creating a connection between kron pam and the kron pam mobile client application docid\ eri2qhfevivndwm0nbjl , enabling multi factor authentication (mfa) docid\ xqasb mfinqkyjtkqc4bk ) log in to kron pam web gui navigate to administration > system configuration manager set these required parameters sc rdp connection otp enabled=true (one time password enabled for rdp connections) sc rdp otp cache enabled=true (if the cache parameter is activated, after entering an mfa the user will not be asked for otp during the cache duration) sc rdp otp cache seconds=240 (otp cache duration in seconds) after these settings, a user belonging to an enabled user group will be asked for a token when logging in to an rdp server note that a gui restart may be required, especially for changes to otp cache for rdp sudo systemctl restart pam gui