Having #MFA for users signing-in is more than a good idea. But what if they forgot or loose their MFA device? Or the data on the smartphone app is lost? Then it's good if you can provide an alternative sign-in method with #recovery codes as a second factor. #Keycloak comes with this option out-of-the-box! You just have to enable the feature and configure the authentication flow appropriately. See this video for all the details you have to know!
📖 Chapters:
0:00 - Intro
0:29 - About Recovery Codes in MFA @ Keycloak
1:10 - Recovery Codes Feature
2:15 - Recovery Codes Required Action
3:20 - Configure all the things (OTP)
4:09 - Configure & create Recovery Codes in Account
5:19 - Sign-in with Recovery Code
8:03 - Authentication Flow for Recovery Codes
11:00 - Weird stuff enabling/disabling the required action ;)
14:38 - Recap, Conclusion & Outro
🔗 Links:
📌 Enabling Features in Keycloak -
https://www.keycloak.org/server/features
📌 Recovery Codes in Keycloak Admin Docs -
https://www.keycloak.org/docs/latest/server_admin/index.html#recovery-codes-recoverycodes
Thank you for watching!
Don't forget to subscribe 🔔 to my channel (if not already done) and give this video some thumbs up 👍 (aka "like").
Tell me about your experiences and in the comments. I'm looking forward to it! Thank YOU!
---
I'm Niko - and I'm an independent freelance software consultant, developer and trainer.
I'm here to help - you, your team and your company.
How can I support you? Just get in contact:
🌎 Website:
https://www.n-k.de
🚧 GitHub Profile:
https://github.com/dasniko
🐦 Twitter:
https://twitter.com/dasniko
🦣 Mastodon:
https://mastodon.cloud/@dasniko
🎥 YouTube Channel:
https://www.youtube.com/@dasniko?sub_confirmation=1
All things Java, JavaScript, All-End (Frontend, Backend, Fullstack Deployments), Authentication, Security 🔐, IAM, Keycloak, Containers, DevOps, Cloud ☁️, Serverless, On-Premise
Please understand that YouTube Comments are not a good place to get support in case of questions and errors. There are forums and groups out there which are the right place to ask!
Тэги:
#keycloak #authentication #auth #oidc #iam #sso #java