Multifactor authentication is a security best practice today, and most organizations require at least two authentication factors for network appliances to meet compliance standards. Two-factor authentication is a security mechanism by which a product authenticates a user at two levels. Access is granted only after successful validation at both levels.
Starting with NetScaler Console 14.1-43.x and later, two factor authentication (2FA) is supported on NetScaler Console on-premises. You can use LDAP, RADIUS, and TACACS as the authentication factors to NetScaler Console on-premises.
Two-factor authentication support is available only for external server authentication.
When a user attempts to log in to a NetScaler Console with two-factor authentication enabled, the user is prompted to enter the user name and password for the initial external authentication. Once the initial authentication is successful, the user is prompted for the second level of authentication.
The user is fully authenticated only after both passwords are successfully validated. If the authentication fails, the reason for the failure is displayed to the user.
If a user is authenticated locally, the user profile must be created in the NetScaler Console database. If the user is authenticated externally then, the user name and password must match the user identity registered in the external authentication server.