Skip to main content

Enforce MFA on privileged accounts

  • July 28, 2026
  • 0 replies
  • 43 views

Forum|alt.badge.img+3

Why enforce MFA on privileged accounts across each capability?

Strong MFA stops credential-stuffing and phishing-driven privileged compromise. 

We encourage our clients to enable MFA at depth by enforcing it for all privileged access across each capability: platform login, password/secret checkout, server login, and privilege elevation. We also recommend using a centralized policy for consistency and compliance.

 

How to set up MFA 

Core platform MFA

Start with core platform MFA in platform Settings > Authentication Profiles. Create identity policies, assigning authentication profiles to users and groups.

Then, assign policies either globally or to specific groups for platform login. We strongly recommend requiring step-up authentication on high-risk operations.   

Delinea supports a variety of common MFA methods: Mobile Authenticator, SMS, email, OATH OTP, FIDO2, RADIUS, Duo, Okta, and more. We recommend deploying FIDO2 for the highest assurance and integrating with your existing IDP. 

Review the technical documentation for setting up MFA, including how to create identity policies and authentication profiles, as these particular points will help you with MFA for each capability. 

 

MFA for Secret Server 

Set MFA for your vault in User settings > Directory Services. Enable it for users as default at user creation or edit existing users. You can also enforce MFA for federated users by unchecking "Platform login via federation satisfies all MFA mechanisms" in Identity Policies. 

 

MFA for Privileged Remote Access 

PRA leverages the platform’s authentication and identity policies. Ensure PRA users/groups are assigned to the appropriate platform identity policy with MFA enabled. 

 

MFA for Server Suite  

Platform MFA for Server Suite requires both Server Suite and Delinea Platform. MFA can be enforced at login and/or privilege elevation.  

To set it up: 

  • Enable the "MFA for Server Suite" feature (open a case with Delinea support if not visible) and, as explained above, configure authentication profiles and identity policies on the platform. 
  • Create authorization policies for login and privilege elevation. 
  • Deploy the IWA certificate to agents. 
  • In Access Manager, assign users to roles that require MFA. 
  • For Linux/UNIX, ensure the agent is joined to the correct zone and group policies are set. For Windows, use group policy to enable MFA for login and/or privilege elevation. 

 

Where and how are you enforcing MFA? Would you add any recommendations to the above?