FortiEDR
FortiEDR automates the protection against advanced threats, pre and post-execution, with real time orchestrated incident response functionality.
YehonatanA
Staff
Staff
Article Id 394132
Description

 

This article describes FortiEDR 2FA prompt frequency, Daily and Weekly calculation, based on 'Last 2FA time'.

 

Scope

 

FortiEDR authentication, Administration -> Users -> Add/Edit User -> Enable Two-Factor authentication for this user -> Edit Prompt Frequency.

 

Solution

 

This article addresses common 2FA-related questions to support understanding of how the security mechanism operates in detail, including:

 

  • How the FortiEDR 2FA Prompt Frequency setting works.
  • When the 2FA prompt frequency timer starts counting.

 

For example, an Admin sets up weekly 2FA for user 'A' on Monday. User 'A' performs the first console login for the first time on Wednesday. Some users are unclear on whether the user will receive the next prompt on Monday (based on the calendar week) or on Wednesday (based on seven days).


The same question applies to the 'daily' setting: For example, the Admin enables a daily 2FA setting. The user receives the 2FA prompt today and enters the OTP, but is not sure when the next prompt will be received from the following options, or in which time zone:

 

  • After 24 hours.
  • After midnight.

 

Understanding how the security mechanism works in detail is important, e.g. for possible incident investigation.

 

FortEDR 2FA Prompt Frequency: Daily and Weekly Calculation Based on 'Last 2FA Time'.

 

When entering the 2FA code, the system saves the current time as the 'last 2FA time'.

Every time the console user logs in, the system checks the time passed since the 'last 2FA time'.

  • If the 2FA policy is set to weekly frequency and the duration from the 'last 2FA time' exceeds 7 days, the user will be prompted to enter the 2FA code again.

  • If the 2FA policy is set to daily frequency and the duration from the 'last 2FA time' exceeds 1 day, the user will be prompted for 2FA.

 

Under Administration -> Users -> Add/Edit User -> Enable Two-Factor authentication for this user -> Prompt Frequency:

 

2faPromptFrequency.png

 

If the Require 2FA option is disabled in Password Policy (FortiEDR 6.2.0 administration guide), 2FA can be enabled for this particular user by checking the Require Two-Factor Authentication for this user checkbox and configuring the 2FA prompt frequency to be AlwaysDaily, or Weekly.

 

For more information regarding 2FA, see the following documents:

Contributors