# Login and Access Security - What are our options

**URL:** <https://forum.mautic.org/t/login-and-access-security-what-are-our-options/27774>\
**Category:** General Discussion\
**Created:** [April 20, 2023, 9:02am UTC](https://forum.mautic.org/t/login-and-access-security-what-are-our-options/27774 "2023-04-20T09:02:48Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![tornmarketing](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/tornmarketing/32/11603_2.png) [@tornmarketing](https://forum.mautic.org/u/tornmarketing)\
**Post date:** [April 20, 2023, 9:02am UTC](https://forum.mautic.org/t/login-and-access-security-what-are-our-options/27774/1 "2023-04-20T09:02:48Z")

</div>

With recent data breaches in our industry, I need to urgently secure mautic  
Mautic as it stands does not comply with any cybersecurity insurance policies.

What options do we have within mautic to limit brute force attacks and broadly speaking implement a 2fa login process?

Be very happy with something basic such as an email/sms code,  
followed up by social only login and lately an authenticator such as google authenticator.

Google authenticators being powerful but a big user barrier, and alot of config / user support

Only protection I have is the firewall/cloudflare and users being smart about their passwords.  
Lastpass breach has all but made the smart passwords rule reliable

---

<div class="post-metadata">

**Author:** ![joeyk](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/joeyk/32/11164_2.png) [@joeyk](https://forum.mautic.org/u/joeyk)\
**Post date:** [April 21, 2023, 4:01pm UTC](https://forum.mautic.org/t/login-and-access-security-what-are-our-options/27774/2 "2023-04-21T16:01:23Z")

</div>

Hi,  
As far as I know there is no reliable solution / plugin.  
I would chip in if you come up with something.  
The Google Authenticator plugin no longer works, although it was fine for years.  
Joey

---

<div class="post-metadata">

**Author:** ![tornmarketing](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/tornmarketing/32/11603_2.png) [@tornmarketing](https://forum.mautic.org/u/tornmarketing)\
**Post date:** [April 22, 2023, 4:43am UTC](https://forum.mautic.org/t/login-and-access-security-what-are-our-options/27774/3 "2023-04-22T04:43:04Z")

</div>

Hey mate

Have you successfully played with the saml sso?  
Haven’t found the best documentation online for this

Got Keycloak up and running

> **[Keycloak](https://www.keycloak.org/)**
>
> Keycloak is an open source identity and access management solution

The SAML docs are rather thin tho

> **[Authentication | Mautic](https://docs.mautic.org/en/authentication)**
>
> . Mautic uses basic authentication for users, however there is the ability to integrate with a SAML SSO provider.SAML Single Sign On. SAML is a single sign on protocol that allows single sign on and user creation in Mautic using a 3rd party user...

> **[SAML Single Sign On (SSO) — Acquia Docs](https://docs.acquia.com/campaign-studio/settings/configuration/saml-sso/)**
>
> SAML Single Sign On (SSO)

Stuck on generating the xml meta file as my mautic nginx setup keeps redirecting to the dashboard  
[https://your-mautic.com/saml/metadata.xml](https://your-mautic.com/saml/metadata.xml)

Can’t find any tutorials or examples of what this metadata.xml is meant to look like for manual config

---

<div class="post-metadata">

**Author:** ![joeyk](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/joeyk/32/11164_2.png) [@joeyk](https://forum.mautic.org/u/joeyk)\
**Post date:** [April 22, 2023, 6:29am UTC](https://forum.mautic.org/t/login-and-access-security-what-are-our-options/27774/4 "2023-04-22T06:29:30Z")

</div>

No, I just wanted to do 2FA as step 1.
