Skip to content

Third-party authenticator support

You can use an authenticator application, such as the Authenticator feature of Sophos Intercept X for Mobile, or any third-party application to authenticate with Sophos Firewall.


Sophos Authenticator reached End of Life (EOL) on July 31, 2022.

We recommend that users migrate to another authenticator app, such as the authenticator feature in Intercept X for Mobile, Google Authenticator, or other apps. See Migrate to another authenticator application.

Authenticator apps you can use

You can use authenticator apps for firewall services that require MFA. Some apps let you use the firewall's QR code. Others require you to manually enter the Base32 secret key.

You can use the following apps:

  • Intercept X for Mobile
  • Google Authenticator
  • Microsoft Authenticator
  • Duo Mobile
  • Okta Verify

These apps support the following firewall services:

  • VPN portal
  • User portal
  • Captive portal
  • Web admin console
  • Remote access SSL VPN
  • Remote access IPsec VPN


On iOS and Android, the QR Code scan doesn't work with the Okta application. To add an account, manually enter the Base32 secret.

On iOS, the QR Code scan doesn't work with Google Authenticator, Duo, and Microsoft Authenticator. To add an account, enter the Base32 secret manually.

Password format

After users scan the QR code or manually enter the Base32 key in the authenticator app, the app starts generating the passcodes.

Users must enter the password in the following format: <password><passcode>