Use Cases for MFA on CTE
When using Multifactor Authentication with CipherTrust Transparent Encryption, after successfully completing the MFA provider, you can enable it on a:
- 
Client 
- 
GuardPoint 
- 
GuardPoint, while exempting certain users/applications/processes from authentication 
Enable Multifactor Authentication on a client
You can enable Multifactor Authentication for all of the GuardPoints on a client. When Multifactor Authentication is enabled at the client level, CTE enforces the configuration for all GuardPoints configured on the client. It overrides any MFA configuration set for individual GuardPoints.
- 
Open CipherTrust Manager > Transparent Encryption application. 
- 
Select the relevant client. 
- 
In the upper pane, select Multifactor Authentication.  
- 
Select Apply. All of the Multifactor Authentication switches are toggled to the on position.  
- 
If the MFA column doesn't display with all switches set to on, click Refresh GuardPoints to display the Multifactor Authentication column.  
Note
To disable Multifactor Authentication on a GuardPoint, deselect Multifactor Authentication in the upper pane and click Apply.
Enable Multifactor Authentication on a GuardPoint
You can enable Multifactor Authentication for individual GuardPoints on clients.
- 
Open CipherTrust Manager > Transparent Encryption application. 
- 
Select the relevant client. 
- 
Select the GuardPoints tab. 
- 
Click the settings icon. 
- 
Select Multifactor Authentication to enable Multifactor Authentication for the GuardPoints.  
- 
Click OK. The Multifactor Authentication column displays.  
- 
Toggle the Multifactor Authentication switch to enable Multifactor Authentication for the selected GuardPoints. 
Note
To disable Multifactor Authentication on a GuardPoint, deselect the Multifactor Authentication toggle switches.
Enable Multifactor Authentication for Client Groups
Multifactor authentication cannot be enabled at the client group level. However, you can enable Multifactor Authentication for individual GuardPoints on client groups.
While propagating the Multifactor Authentication-enabled GuardPoints to the member clients, CipherTrust Transparent Encryption checks the Multifactor Authentication capability of the member clients. If a client is Multifactor Authentication-capable, the GuardPoints are added to the client. If a client is not Multifactor Authentication-capable, the GuardPoints are skipped.