Introduce other MFA methods besides the phone app
As for now, MFA extension is limited only to a phone app. It would be useful to introduce other authorization methods (e.g. mail) for this extension.
Thank you for your suggestion. We will consider this functionality in upcoming releases if it is popular. Everyone, please continue voting for this feature if you consider it important.
-- KvD
-
Kaspar commented
This is a request for the implementation of an optional extra layer of authentication via email for customers and resellers who want to login to a Plesk server. Which would improve security by making it much less effective/useful for customers to share their login details with others.
Although similar in concept to 2FA, this is different than the already available 2FA extension as "email account authentication" poses way less of a barrier to non tech savvy users as no additional apps or devices are needed for authentication. Just email.
Ideally it would work something like this: a server administrator could enable "email account authentication" so customers and resellers would be emailed an additional code they are required to enter after they login. The code gets sent via email to the customer after they login with their regular login details (username and password). It would be nice if the server administrator could configure an interval which would allow customers to skip the "email account authentication" for an X number of days (in panel.ini for example). So customers don't always have to enter the code emailed to them every time they login, but only once every X days.
(I can see this feature being useful for additional administrator accounts as well. But my main focus is on customers and resellers)
Use case:
Rather than creating separate login accounts for others who need access to a Plesk account, quite some customers easily share their own Plesk login details. For example with their (local) IT expert, their web developer or even friends and family. Which of course is not really a good security practice. To mitigate this issue email account authentication would be really useful.I realize this is probably a niche request, but I do think this might be of interest to quite some system administrators as it gives a some peach of mind. So hopefully this feature will find it's way in to Plesk.
-
j commented
can you please implement the Two-factor Authentication via text message?