Tools

How to configure MFA in Serv-U

This article describes how to configure MFA in Serv-U MFT

First published date

5/20/2023 3:34 PM

Last published date

8/6/2026 2:54 PM

Overview

What is MFA in Serv-U

In addition to the password-based authentication, Serv-U implements optional authentication by means of a so-called TOTP - Time-based one-time password. 

A User who will use MFA for logging in a Serv-U server will have to create their own additional MFA Account and register it on their own device that may run an Authenticator that supports TOTP based authentication. 

Serv-U offers the TOTP-based authentication parameterized with the following details:

  • Number of Digits: 6 (six)
  • Generated password expiration time: 30 seconds
  • HMAC Algorithm: SHA-1

MFA availability

  • Serv-U supports MFA only for user web (HTTP) sessions; MFA is not available for FTP(S) or SSH FTP connections.
  • MFA is supported exclusively for local Server and Domain users; this functionality has been enhanced in Serv-U 2026.3, where MFA support has been extended to include both Microsoft Windows (Active Directory) and LDAP users.
  • Starting with Serv-U version 15.5, MFA support has been extended to include Database users.
  • MFA was introduced starting version 15.4

Multifactor authentication can provide an additional layer of security. When it is set up, users are prompted to enter a six-digit code sent by a third-party app in addition to their username and password. Serv-U supports a variety of multifactor authentication apps.

Product section

Serv-U Managed File Transfer & Serv-U FTP Server

Resolution

Configuring Ser-U MFA

Multifactor authentication is disabled by default. 
Therefore, after updating an existing Serv-U Server to version 15.4.0, the users' authentication method will not change.
Serv-U administrators can choose to enable it (users can enter a code but are not required to) or enforce it (users must enter a code to log in).
Multifactor authentication can be configured at the globaldomaingroup, or user level.