Using MFA for RDP Connections
to activate mfa for an rdp connection admin and users have the qr code, installed the kron pam mobile client application , scanned the qr code with the kron pam mobile client application , and otp is enabled for the user group that will be using mfa for rdp connections (see sections sending the mfa qr code to users docid\ foxcgsrfkdettlnic4rrk , creating a connection between kron pam and the kron pam mobile client application docid\ tgayn5p3ww98d6agow2ya , enabling multi factor authentication (mfa) docid\ rz mdb8kufoscu7gl9wn5 ) log in to kron pam web gui navigate to administration > system configuration manager set these required parameters sc rdp connection otp enabled=true (one time password enabled for rdp connections) sc rdp otp cache enabled=true (if the cache parameter is activated, after entering an mfa the user will not be asked for otp during the cache duration) sc rdp otp cache seconds=240 (otp cache duration in seconds) after these settings, a user belonging to an enabled user group will be asked for a token when logging in to an rdp server note that a gui restart may be required, especially for changes to otp cache for rdp sudo systemctl restart pam gui