SSO MFA integration & security best practicesSolved

Participant
Discussion
3 days ago May 22, 2026

Hey everyone, 

My organization already uses Microsoft Entra ID (Azure) and Okta for all our corporate logins. Instead of managing separate MFA codes inside the Hexnode portal, is there a way to just “offload” the authentication to our existing Identity Providers? 

Replies (3)

Marked SolutionPending Review
Hexnode Expert
3 days ago May 22, 2026
Marked SolutionPending Review

Hey @ethan_Absolutely. If you’re already using an IdP, it’s much more efficient to enforce MFA at that level. This way, your technicians are challenged by your corporate security policies before they even reach the Hexnode portal. 

To set this up: 

  1. Navigate to Admin > Logon Restrictions. 

  1. Scroll to Global SSO Login Settings. 

  1. Under Allowed SSO loginscheck the boxes for your providers (Microsoft, Google, or Okta). 

Once enabled, you can essentially let your IdP handle the “heavy lifting” of multi-factor verification. 

Marked SolutionPending Review
Participant
3 days ago May 22, 2026
Marked SolutionPending Review

That’s perfect. One more thing—what happens if one of my admins loses their phone or their Authenticator app starts giving “Invalid Code” errors? Is there a “break-glass” procedure? 

Marked SolutionPending Review
Hexnode Expert
3 days ago May 22, 2026
Marked SolutionPending Review

Great questions. Here is a quick reference table for those scenarios: 

Issue 

Solution 

Invalid App Code 

Ensure the phone’s time/date settings are set to Automatic. TOTP codes are time-sensitive; even a one-minute drift will cause a failure. 

Lost Device 

A Super Admin can go to that technician’s profile and click Reconfigure Authenticator app. This kills the old link and generates a new QR code. 

Portal Lockout 

Best Practice: Always have at least two Super Admins with MFA enabled on different devices. This prevents a single point of failure from locking you out. 

Important Note on Session Security: 

Hexnode will automatically force a logout if someone tries to log into the same account from two different browsers or devices at the same time. We also recommend setting up a Logout Automatically timer under the technician’s profile for added security! 

Save