Zyxel USG FLEX H Firewall - Which MFA Methods Are Supported in uOS for Outbound Authentication

Multi-Factor Authentication (MFA) helps to improve security by adding an extra verification step during user login. In uOS (Unified Operating System), MFA can be used with outbound user databases, where authentication is handled by external or cloud-based identity systems.

This article gives a clear overview of:

  • supported outbound user databases in uOS,

  • applications and access methods (VPN, SSL VPN, Captive Portal),

  • available MFA methods,

  • user enrollment options,

  • current feature availability and limitations.

This information is useful for administrators who want to plan or configure MFA on Zyxel devices running uOS.

MFA Architecture in uOS (Outbound Authentication)

In outbound authentication scenarios, the Zyxel firewall sends user authentication requests to an external service or identity provider. uOS does not always manage the second factor directly. In many cases, MFA is handled by the external system.

Supported outbound user databases include:

  • Zyxel CloudAuth

  • Microsoft Entra ID / Google Identity

  • Nebula Entra ID

  • External Active Directory

  • Local users on the device

Depending on the scenario, MFA can be provided by:

  • built-in methods (for example, Google Authenticator or email OTP),

  • third-party MFA services (for example, Microsoft Entra MFA or Duo Security).

Supported MFA Scenarios in uOS

The table below shows which MFA methods are supported in uOS, based on the user database and application type.

MFA options in uOS with outbound user databases

Directory / IdPApplication / ProtocolAuth ClientMFA MethodEnrollmentAvailability in uOSRemarks
CloudAuthIPSec VPNSecuExtenderGoogle AuthenticatorUser via CloudAuthPlanned (July 2026)FLEX / ATP supported
CloudAuthIPSec VPNSecuExtenderPasskeyUser via CloudAuthPlanned (July 2026)
CloudAuthSSL VPNBrowserGoogle AuthenticatorUser via CloudAuthPlanned (July 2026)uOS only
CloudAuthCaptive PortalBrowserPasskeyUser via CloudAuthPlanned (July 2026)
Entra ID / GoogleSSL VPNOpenVPN clientMFA by IdPVia IdPYes (uOS 1.37)OIDC required
Entra ID / GoogleCaptive PortalBrowserMFA by IdPVia IdPYes (uOS 1.37)OIDC required
Entra ID / GoogleIPSec VPNSecuExtenderMFA by IdPVia IdPNot Planed
External ADIPSec VPNSecuExtenderEmail / SMS OTPServer-sideYesFLEX / ATP only
External ADIPSec VPNSecuExtenderDuo MFAVia DuoYes
External ADSSL VPNBrowser / PAPDuo MFAVia DuoYes
Nebula Entra IDSSL VPNOpenVPN clientEntra ID MFAVia Entra IDNot Planed
Local (device)IPSec VPNSecuExtenderGoogle AuthenticatorAdmin enrollYesuOS & ZLD
Local (device)SSL VPNSecuExtenderGoogle AuthenticatorAdmin enrollYesuOS only

Notes and Limitations

  • MFA by IdP means that MFA is fully handled by the external identity provider.

  • Some MFA options are available only in uOS and are not supported on older platforms.

  • CloudAuth MFA and Passkey support for uOS are planned features and not available yet.

  • Duo Security integration requires additional configuration. Separate guides are available.

  • MFA support depends on the application type and the client used (browser, SecuExtender, OpenVPN).

Articles in this section

Was this article helpful?
0 out of 0 found this helpful
Share

Comments

0 comments

Please sign in to leave a comment.