QS-WAN · Access

MFA you can count, device by device

Multi-factor authentication, or MFA, is a per-device state in QS-WAN rather than a policy you declare. Every VPN device carries an MFA column, and the console counts how many have it enabled. Turning it on for a user needs a gateway, and the enrollment QR code travels inside the encrypted archive that carries the profile.

What it is

What multi-factor authentication is here

MFA is the second proof of the person. A certificate proves a machine holds a private key generated on that machine, which is what device enrollment does. MFA asks whether the right human is in front of it.

Four places

The Create a user dialog

The field reads select a gateway to enable MFA, so the dependency meets you before you save instead of after.

A column of its own

It sits in the VPN devices table, so coverage is read off the inventory rather than reconstructed from somebody memory.

A tile with the count

How many devices in the fleet have it enabled, on the face of the console, without anybody counting rows.

A permanent configuration check

One of three in Mission Control, beside Cryptography and Certificates. On a gap it changes on its own and reads as critical.

One proof alone is not a session. The certificate answers for the machine, the code answers for the person, and the gateway opens when both arrive. What makes it countable is that the answer lives on the device row, and the next section lets you move it.

The mechanism

One gap, and the four readings that agree about it

Press the buttons on the panel. Try to enable multi-factor on the supplier account first, before it has a gateway, and watch it refuse for the reason the dialog gives you in the product.

VPN devices Device Gateway Multi-factor Laptop Gateway 1 Enabled Not enabled Workstation Gateway 1 Enabled Not enabled Supplier account No gateway Enabled Not enabled Devices with multi-factor 2 of 3 Mission Control check Multi-factor authentication Critical Clear one of three Risk driver MFA coverage gap Counting Quiet posture group Turning it on Select a gateway Sealed profile archive QR on their own screen A profile can exist without a gateway. Multi-factor cannot.
Two of three. The supplier account has no gateway yet.

The diagram shows the VPN devices table with three rows. A laptop and a workstation sit on Gateway 1 with multi-factor enabled. A supplier account has no gateway and no multi-factor. Three readings on the right count that same column: the number of devices with multi-factor, which reads two of three; the Mission Control configuration check, which reads critical while there is a gap; and the risk driver called MFA coverage gap, which is counting. Press Enable multi-factor on the supplier account and nothing happens, because there is no gateway and the dialog says so before you save. Press Attach a gateway, then Enable multi-factor, and all four readings move at once: the column says enabled, the count reads three of three, the check reads clear and the driver goes quiet. Underneath runs the channel that carries it: select a gateway, the sealed profile archive, and the QR code shown on the screen of the person.

Nothing on that panel is a report you asked for. The column is the inventory, the count is the same column added up, the check runs whether or not anybody is looking, and the driver is that same fact with a price on it. Four readings, one source, which is why they cannot quietly disagree.

Why this exists

Four things that go wrong without it

The coverage export somebody ticked by hand

It is right the day it is written and stale the day a supplier gets an account. Nothing in it tells you who was added last week.

A ticket from March standing in for the answer

Coverage held in a ticket and in the memory of whoever set up the last three users is coverage you rebuild every time it is asked, and rebuild slightly differently each time.

The account opened during a cutover

Somebody created it, the work finished, and nobody revisited it. Without a column to sort, an account like that stays invisible until an audit finds it.

Evidence gathered the month before the audit

Reconstructing coverage in a hurry is the opposite of evidence accumulating week by week, and the hurry is the part that gets noticed.

What you gain

The same column, read by two people

If you run the network

Coverage stops being a spreadsheet

Sort the VPN devices table by the MFA column and there is the list of who is still without it, including the supplier account somebody opened during a cutover and nobody revisited.

Nobody has to remember to check. The Mission Control check is permanent, it changes on its own, and it is sitting there on a morning when coverage was the last thing on your list.

If you sign for it

A gap moves one named number

A gap moves a driver in the risk score called MFA coverage gap, one of 19 that all carry the same weight. When the score moves you can point at the driver that moved it.

That is evidence accumulating week by week instead of being reunited the month before an audit, which is the difference between showing somebody a record and showing them an effort.

How it works

Three steps to a device with MFA on it

You pick the gateway while you create the user

The MFA field in the Create a user dialog asks you to select a gateway. A profile can exist without one, so you can license somebody today and give them a gateway later. MFA cannot. No gateway, no MFA, and the dialog says so before you save.

The enrollment QR travels sealed

The profile goes out inside an encrypted archive. The handshake that opens it is hybrid: Kyber768 encapsulation and ECDH P-384, combined through HKDF-SHA256, and the key opens an AES archive. Where MFA is on, the QR code rides in that same archive, rather than in an email or behind a link somebody can forward.

The person reads it off their own screen

The QR appears on the profile screen of the QNova Client. They open the app, they see it, they enroll. Nothing was emailed to them that would still work if it were forwarded.

Before you start

You need a gateway the person can reach, and the QNova Client on their device. The profile itself can come first, which is why licensing somebody and giving them a gateway are two separate decisions rather than one.

In detail

The three things to check before you commit

Dependency

What a gap in the column is actually telling you

The gateway dependency has a shape, and the column tells you which of the two cases you are looking at before you go and ask anybody.

  1. Somebody nobody has attached to a gateway yet. The profile exists, the gateway decision has not been taken, and MFA cannot be enabled until it is.
  2. Somebody with a gateway who has not enrolled. The switch is on, the QR went out in the sealed archive, and the person has not opened it yet.

Two different gaps, two different jobs. One is a decision you owe them, the other is a nudge they owe you, and the column separates them without a meeting.

Envelope

The envelope is the one the certificates already use

Nothing about the archive is specific to MFA, which is the point: the enrollment secret gets exactly what certificate delivery gets. A hybrid handshake, Kyber768 encapsulation and ECDH P-384 combined through HKDF-SHA256, and a key that opens an AES archive.

100% of communications are encrypted, always with post-quantum cryptography, including the establishment of the tunnels. The QR code is a passenger in a channel that was already built to that standard, which is why turning MFA on adds a step for the person and no new path for the secret.

Arithmetic

The risk arithmetic is written down, not asserted

MFA coverage gap sits in the posture group, beside weak cryptography and certificate expiry. It scales by how close the gap is to its own saturation point, and each of the 19 drivers is worth about 5.26 points out of 100.

So the number is checkable rather than believable, which is the only kind worth putting in front of somebody who has to sign underneath it.

The change

The Monday the check turns critical

Nothing physical moves. Same people, same devices, same gateways. What changes is where the fact lives.

Before

Coverage is something you rebuild

It lives in an export somebody ticked by hand, a ticket from March, and the memory of whoever set up the last three users. You rebuild the answer every time it is asked, and it goes stale the day a supplier gets an account.

After

Coverage arrives on its own

It is a column on the inventory, a count on a tile, a check that changes by itself and reads as critical, and a named driver in the score. You did not go looking for the gap. The gap came to you.

Works better together

Where this sits in the rest of the console

These are not a related links box. Each one owns a piece of the same device row, and the order is the order a person meets them.

01

Where a profile is created and a gateway is picked, which is the dialog the MFA field lives in. The gateway decision is taken there, not here.

02

Puts the first certificate on the device and keeps the private half local. That is the machine half of the answer, and this page is the other half.

03

Owns the sealed archive the QR code travels in, and everything else that reaches a device by the same route.

04

Turns a coverage gap into a number that moves, so the gap has a price somebody can point at rather than a feeling somebody has about it.

The access problem all of this belongs to is secure remote access, and every feature is listed in one place.

What this does not do

The limits, because they are what make the rest believable

It does not work without a gateway

That is the dependency, said plainly, because you meet it in the first hour. A profile can wait for its gateway. Multi-factor cannot.

It is switched on per profile, and read per device

The switch lives on the user profile against a gateway. The column, the count and the check read it device by device, which is how you find a gap, but the action you take is on the profile.

It does not prove the device

That is the certificate and the enrollment behind it. MFA is the human half of the answer, and a page that told you it was the whole answer would be selling you something.

It does not chase anybody

The console shows you who has not enrolled. It does not phone them, and neither do we: this is a product, not a managed service.

Questions people ask

The ones that come up first

What does MFA stand for?

MFA stands for multi-factor authentication: proving who somebody is with more than one factor instead of a password alone. In QS-WAN it is enabled per user profile against a gateway, and the person enrolls from a QR code on their own profile screen.

How does the enrollment code reach the user?

Inside the same encrypted archive that carries the profile, opened by a hybrid handshake of Kyber768 and ECDH P-384 through HKDF-SHA256. The QR code is then shown on the profile screen of the client, so nothing usable travels by email.

How do I find who still does not have MFA?

Three places, and they agree: the MFA column in the VPN devices table, the tile that counts the fleet, and the Mission Control check, which reads as critical while there is a gap.

Can I enable MFA for somebody who has no gateway?

No. A profile can exist without a gateway, so you can license somebody today and attach a gateway later, but multi-factor needs one. The Create a user dialog says so before you save rather than after.

Does a missing MFA change our risk number?

Yes. The driver is called MFA coverage gap, it sits in the posture group, and it weighs the same as the other 18. When the score moves you can name the driver that moved it.

Bring us your fleet. We will sort the column with you.

An engineer, a console shaped like yours, and as long as you need. You sort the VPN devices table by the MFA column and see who is still without it. It is free and there is nothing to sign.

Scroll to Top