Skip to main content

Mac Login Integration

SecTrail MFA provides multi-factor authentication for macOS operating system login.

Features​

πŸ” Login Screen Authentication​

SecTrail MFA is activated during the macOS login process. MFA verification is performed when the user turns on the computer or switches users.

IMPORTANT

MFA verification is only active on the login screen. MFA is NOT activated during the lock screen state.

πŸ‘₯ Multiple Account Support​

  • MFA for multiple user accounts on the same Mac
  • Admin and standard user distinction
  • User-based policies

Configuration​

SecTrail MFA Side​

  1. API Client: Create an Agent-type API client for the API credentials required during SecTrail Credential Provider installation
  2. Application Profile: Create an API-type application profile for Mac Login factor configuration
  3. Authentication Methods: Add desired authentication methods (Push, SMS OTP, Soft OTP, etc.) to the application profile

macOS Side​

SecTrail MFA Pluggable Authentication Module (PAM) is installed on the macOS system.

Installation Steps​

macOS Installation Step 1

Step 1: Installation wizard welcome screen - API settings come pre-configured

macOS Installation Step 2

Step 2: Detailed information about configuration file and components to be installed

macOS Installation Step 3

Step 3: Installation destination selection - Installation is performed for all users on the computer

macOS Installation Step 4

Step 4: Installation type confirmation - Click Install button to start installation

macOS Installation Step 5

Step 5: Installation in progress - Configuring plugin and copying files

macOS Installation Step 6

Step 6: Installation completed successfully - MFA plugin is now active for login/logout

Supported Authentication Methods​

Authentication methods available for macOS Login integration:

  • LDAP Authentication: Authentication with Active Directory or LDAP server
  • Local Authentication: Authentication with SecTrail MFA's local user database
  • LDAP+OTP: Two-factor authentication with password + OTP on a single screen
  • Soft OTP: Time-based one-time password with mobile app (SecTrail Authenticator)
  • SMS OTP: One-time password sent via SMS
  • Mail OTP: One-time password sent via email
  • Push Notification Authentication: Approval via push notification through mobile app (SecTrail Authenticator)
  • Approved OTP: Authentication with pre-approved OTP codes
INFORMATION

Sudo privileges are required for macOS PAM module installation.