SMSEagle can send a one-time passcode by SMS, or check one from an authenticator app, before letting anyone into the web interface. Turn it on for your own account, assign it to specific users, or make it mandatory for everyone.
Multi-factor authentication also asks for a one-time code from a phone, so the password alone is not enough.
MFA in SMSEagle helps you meet that requirement: turn it on for chosen accounts or enforce it for everyone.
Open Account settings > Security, pick a method, and confirm it once. No administrator needed for your own account.
An administrator can assign a method to any account from System > Users. The user finishes the setup themselves at their next sign-in.
Force MFA for all users, only new users, or turn enforcement off entirely – from one policy field in Settings > Application.
Choose your method
Pick Multi-Factor Authentication via SMS for a code sent to the phone on file, or Authenticator Application for a time-based code from an app such as Google Authenticator, after a one-time QR scan.
Active after the first code
Enabling a method does not make it live yet – it still has to be confirmed. Scan the QR code or wait for the SMS, then enter the code once to finish the setup.
One code, then you're in
After the password, the device asks for the current code from SMS or the authenticator app. A wrong code simply asks again – no lockouts, no support ticket.
Assign it directly
An administrator picks None, SMS, or Authenticator app for any user. The account is set to require that method, and the person finishes the setup themselves at their next sign-in.
Or make it mandatory
Apply Force MFA to all users, and once the policy is saved it applies to every account straight away – nobody signs in again without it.
SMSEagle hardware SMS gateway
SMSEagle combines hardware and software into a single, self-contained gateway. It is designed for critical environments, so security is built in from the ground up, confirmed by CE, FCC, ISED, UKCA, PTCRB, RCM, IMDA, TDRA, CB Scheme, GCF, carrier certifications (Verizon, AT&T) and ISO 27001.
After the password is accepted, the device asks for a one-time code sent by SMS or generated by an authenticator app, so a stolen password alone is not enough to sign in.
Multi-Factor Authentication via SMS, and an Authenticator Application such as Google Authenticator, set individually per account.
Yes. Settings > Global settings > Application has a Force MFA policy: do not force, for new users only, or for all users.
Every account with MFA enabled holds a single-use recovery code, accepted in place of the one-time code. Once it is used, a new one is created automatically.
No. MFA guards the web sign-in only. HTTP API requests authenticate with an access token and are unaffected.
Yes, MFA is a built-in feature available on all current SMSEagle hardware SMS gateways.