Two-factor authentication in the public cloud
VMware Cloud Director® supports two authentication methods: local user database and Single Sign-On (SSO) via the SAML protocol.
You can enable two-factor authentication using any service. With the Multifactor solution, you can enable two-factor authentication via SSO for individual users. Local authentication will work in parallel. In Cloud Director, the user database for local access and SSO access will be shared.
Enable two-factor authentication via Multifactor
- Order and configure Multifactor two-factor authentication.
- Create a SAML application.
- Configure the SAML application.
- Add users.
1. Order and configure Multifactor two-factor authentication
Use the instructions Order and configure Multifactor two-factor authentication.
2. Create a SAML application
- In the Multifactor control panel, go to Resources.
- Click Add resource.
- In the Site block, select SAML application.
- Enter the resource name.
- Select an identity provider.
- If you selected Active Directory, enter the portal address.
- Optional: to automatically create a user in Multifactor upon their first authorization in Cloud Director, enable the Register new users toggle.
- Optional: to require the user to self-configure 2FA and prevent authorization in Cloud Director without it, select the Enable self-configuration/Deny access checkbox.
- Click Save.
- On the SAML application page, in the Multifactor Metadata block, download the SAML application metadata file.
3. Configure the SAML application
-
From the control panel, open the Cloud Director panel: Cloud powered by VMware → Cloud Director.
-
Open the Administration tab.
-
Go to Identity Providers → SAML.
-
Click Configure.
-
Open the Service Provider tab.
-
In the Entity ID field, paste your cloud address:
- Moscow —
https://vcd-msk.selectel.ru/tenant/<s-xxxx>/ - Saint Petersburg —
https://vcd.selectel.ru/tenant/<s-xxxx>/
Specify
<s-xxxx>— the organization name; you can view it in the Cloud Director address bar or in the control panel under Cloud powered by VMware in the list of organizations. - Moscow —
-
Open the Identity Provider tab.
-
Enable the Use SAML Identity Provider toggle.
-
Upload the SAML application metadata file.
-
Click Save.
-
Open the Service Provider tab.
-
In the Service Provider Metadata field, click Retrieve Metadata. The metadata file will be downloaded to your device.
-
In the Multifactor control panel, go to Resources.
-
In the row with the SAML application, click Settings.
-
In the Service Provider block, click Upload metadata and upload the file.
4. Add users
- From the control panel, open the Cloud Director panel: Cloud powered by VMware → Cloud Director.
- Open the Administration tab.
- Go to Access Control → Users.
- Click Import Users.
- Enter the logins of the users who will be able to connect via SSO.
- Select the role to be assigned to the users.
- Click Save.
Log in with two-factor authentication
- From the control panel, open the Cloud Director panel: Cloud powered by VMware → Cloud Director.
- In the top right corner, in the menu, select Log out.
- The Selectel vCloud Director Logout Page will open.
- Click Login with Single Sign On.
- Sign in with your provider account.
- A one-time code will be sent to the Multifactor application.
- Enter the code.