Two factor authentication for crx | Community
Skip to main content
September 24, 2020
Solved

Two factor authentication for crx

  • September 24, 2020
  • 3 replies
  • 1647 views

Hi Team,

  We are trying to implement MFA for AEM and referred this blog. 

However we are not sure how this can be done for crx explorer as well. 

 

http://localhost:4502/crx/explorer/index.jsp

 

Please can someone suggest any pointers?

 

Regards,

Jay 

This post is no longer active and is closed to new replies. Need help? Start a new post to ask your question.
Best answer by Jineet_Vora

Hello @jay1122,

Considering it is CRX Explorer where limited access (only admins) is required, what's the use case which requires you to set up MFA on CRX level? Generally MFA is for business users on AEM welcome page where they do not have access to CRX at all.

 

There should always be a back door entry. If anything goes wrong in MFA authentication how would admins be able to login to AEM CRX? Also, changing core login mechanism is highly risky.

Jineet

3 replies

Jineet_Vora
Community Advisor and Adobe Champion
Jineet_VoraCommunity Advisor and Adobe ChampionAccepted solution
Community Advisor and Adobe Champion
September 24, 2020

Hello @jay1122,

Considering it is CRX Explorer where limited access (only admins) is required, what's the use case which requires you to set up MFA on CRX level? Generally MFA is for business users on AEM welcome page where they do not have access to CRX at all.

 

There should always be a back door entry. If anything goes wrong in MFA authentication how would admins be able to login to AEM CRX? Also, changing core login mechanism is highly risky.

Jineet

jay1122Author
September 24, 2020
Hello @jineet_vora, Yes you are correct, biz users do not have access to crx explorer and only admins does. Our client is expecting to implement MFA and does not want to descope admin/developers We have multiple vendors accessing AEM so in our case it is understandable as to why client feels so..
Nikhil-Kumar
Community Advisor
Community Advisor
September 24, 2020

@jay1122 

For using MFA for crx/explorer you might need to touch the OOTB functionality as @jineet_vora  suggested which is not recommended or risky. 

@joerghoh @vanegi  Can you provide your views ?

Thanks,
Nikhil Kumar

joerghoh
Adobe Employee
Adobe Employee
September 24, 2020

Ah. the good old CRX Explorer ... I don't think that this is possible, because it solely relies purely on JCR authentication and does not use Sling.