Skip to content

Migrate to another authenticator application

If you've configured multi-factor authentication that uses an authenticator generating passcodes, users may need to rescan the QR code later.

For example, you may want users to migrate to another authenticator app, or a user may have lost their mobile device and doesn't have a backup. For supported authenticator apps, see Third-party authenticator support.

Delete issued tokens in the firewall

You must stop allowing passcodes generated by the previous authenticator application. Do as follows on the web admin console:

  1. Go to Authentication > Multi-factor authentication.
  2. Under One-time password (OTP), make sure Generate OTP token with next sign-in is turned on.
  3. Select Email to send the QR code to users by email or Portals to show the QR code in the user and VPN portals the next time they sign in.
  4. Under Issued tokens, select the users using the unsupported application and click the delete button Delete button..

Users rescan the QR code

The users whose tokens you've deleted must do as follows:

  1. Sign in to the VPN or user portal using only the password.

    They must not enter the passcode generated by the old app because it becomes invalid.

    If Share QR code is set to Portals, the QR code appears. If it's set to Email, the QR code is sent to the user's email address.

  2. Scan the QR code shown using a supported authenticator app.

  3. Sign in to the VPN or user portal using the password followed by the generated passcode. For example, <password><passcode>.

    Note

    If you don't use the QR code to sign in within 24 hours of generating it, the QR code expires. To generate a new QR code, sign in using only your password.