NextGen Knowledge Center

Excluding Users from MFA

You may have users that need to be able to authenticate without going through MFA. For example, a custom integration against the REST API. An administrator can exclude users from the MFA settings tab.

MFA Required column for users in Multi-Factor Authentication Settings section

This is available in both TOTP and Duo modes. Note that in the case of Duo, you can also set a user to "bypass" mode in the Duo Admin Panel. The user will be able to login without using a secondary device. However since communication still needs to be made to Duo even in bypass mode, depending on the integration you may need to exclude the user here on the MFA settings tab instead.