Tools
How to configure MFA in Serv-U
This article describes how to configure MFA in Serv-U MFT
First published date
Last published date
Overview
What is MFA in Serv-U
In addition to the password-based authentication, Serv-U implements optional authentication by means of a so-called TOTP - Time-based one-time password.
A User who will use MFA for logging in a Serv-U server will have to create their own additional MFA Account and register it on their own device that may run an Authenticator that supports TOTP based authentication.
Serv-U offers the TOTP-based authentication parameterized with the following details:
- Number of Digits: 6 (six)
- Generated password expiration time: 30 seconds
- HMAC Algorithm: SHA-1
MFA availability
- Serv-U supports MFA only for user web (HTTP) sessions; MFA is not available for FTP(S) or SSH FTP connections.
- MFA is supported exclusively for local Server and Domain users; this functionality has been enhanced in Serv-U 2026.3, where MFA support has been extended to include both Microsoft Windows (Active Directory) and LDAP users.
- Starting with Serv-U version 15.5, MFA support has been extended to include Database users.
- MFA was introduced starting version 15.4
Multifactor authentication can provide an additional layer of security. When it is set up, users are prompted to enter a six-digit code sent by a third-party app in addition to their username and password. Serv-U supports a variety of multifactor authentication apps.
Product section
Resolution
Configuring Ser-U MFA
Multifactor authentication is disabled by default.
Therefore, after updating an existing Serv-U Server to version 15.4.0, the users' authentication method will not change.
Serv-U administrators can choose to enable it (users can enter a code but are not required to) or enforce it (users must enter a code to log in).
Multifactor authentication can be configured at the global, domain, group, or user level.