[GH-ISSUE #5088] Add MFA to Local Users #9877

Closed
opened 2026-08-05 01:23:49 -04:00 by saavagebueno · 21 comments
Owner

Originally created by @Discolor3182 on GitHub (Jan 11, 2026).
Original GitHub issue: https://github.com/netbirdio/netbird/issues/5088

Originally assigned to: @jnfrati on GitHub.

Hello,

Please add MFA to local users

Thank you.

Originally created by @Discolor3182 on GitHub (Jan 11, 2026). Original GitHub issue: https://github.com/netbirdio/netbird/issues/5088 Originally assigned to: @jnfrati on GitHub. Hello, Please add MFA to local users Thank you.
saavagebueno added the feature-request label 2026-08-05 01:23:49 -04:00
Author
Owner

@Camis commented on GitHub (Jan 11, 2026):

Yes, this is must have!

<!-- gh-comment-id:3735086405 --> @Camis commented on GitHub (Jan 11, 2026): Yes, this is must have!
Author
Owner

@ashokjp2 commented on GitHub (Jan 11, 2026):

Yes +1, must have considering this opens access to the entire network. Also currently I cant find option to even change password to make it more secure. If we had atleast MFA, then that issue could have waited.

<!-- gh-comment-id:3735408857 --> @ashokjp2 commented on GitHub (Jan 11, 2026): Yes +1, must have considering this opens access to the entire network. Also currently I cant find option to even change password to make it more secure. If we had atleast MFA, then that issue could have waited.
Author
Owner

@obale commented on GitHub (Jan 17, 2026):

+1

My current workaround is to add an Identity Provider via the dashboard, transfer ownership status to an IdP account and block the internal admin user.

<!-- gh-comment-id:3764774467 --> @obale commented on GitHub (Jan 17, 2026): +1 My current workaround is to add an Identity Provider via the dashboard, transfer ownership status to an IdP account and block the internal admin user.
Author
Owner

@ashokjp2 commented on GitHub (Jan 18, 2026):

There is no way I see to block or disable the internal user. Please let me know if I am missing something. If i delete, what happens to the device / peers mapped to the initial owner user account.

<!-- gh-comment-id:3765658160 --> @ashokjp2 commented on GitHub (Jan 18, 2026): There is no way I see to block or disable the internal user. Please let me know if I am missing something. If i delete, what happens to the device / peers mapped to the initial owner user account.
Author
Owner

@obale commented on GitHub (Jan 18, 2026):

In my case I connected an external IdP, logged in with an IdP account first and made it Owner. After that under the Users page there is a switch allowing to block the internal user.

The internal account does not have any peers or resources. It was a new setup. This may not work for most setups though.

<!-- gh-comment-id:3765664243 --> @obale commented on GitHub (Jan 18, 2026): In my case I connected an external IdP, logged in with an IdP account first and made it Owner. After that under the Users page there is a switch allowing to block the internal user. The internal account does not have any peers or resources. It was a new setup. This may not work for most setups though.
Author
Owner

@ashokjp2 commented on GitHub (Jan 18, 2026):

Perfect, thankyou. anyway to move peers and devices to the new admin as well?
If so that solves my problem temporarily :)

<!-- gh-comment-id:3765666661 --> @ashokjp2 commented on GitHub (Jan 18, 2026): Perfect, thankyou. anyway to move peers and devices to the new admin as well? If so that solves my problem temporarily :)
Author
Owner

@obale commented on GitHub (Jan 18, 2026):

netbird down and netbird up on the device or logout and login with new account!?! I am not aware of an automated migration approach.

<!-- gh-comment-id:3765669414 --> @obale commented on GitHub (Jan 18, 2026): netbird down and netbird up on the device or logout and login with new account!?! I am not aware of an automated migration approach.
Author
Owner

@LorenzoVaccher01 commented on GitHub (Feb 3, 2026):

+1!!!!

<!-- gh-comment-id:3841123629 --> @LorenzoVaccher01 commented on GitHub (Feb 3, 2026): +1!!!!
Author
Owner

@heymoe commented on GitHub (Feb 3, 2026):

My guess is Netbird is waiting on Dex to add 2FA support before it will add that functionality to local user management without having to use a 3rd party / external IdP provider. I found this thread tracking the progress of adding 2FA to Dex if anyone is interested in following the progress:

https://github.com/dexidp/dex/pull/3712

<!-- gh-comment-id:3843533979 --> @heymoe commented on GitHub (Feb 3, 2026): My guess is Netbird is waiting on Dex to add 2FA support before it will add that functionality to local user management without having to use a 3rd party / external IdP provider. I found this thread tracking the progress of adding 2FA to Dex if anyone is interested in following the progress: https://github.com/dexidp/dex/pull/3712
Author
Owner

@proteus88 commented on GitHub (Feb 5, 2026):

For small deployments this is a must have. +1

<!-- gh-comment-id:3853555082 --> @proteus88 commented on GitHub (Feb 5, 2026): For small deployments this is a must have. +1
Author
Owner

@adrianbaena commented on GitHub (Feb 25, 2026):

If anybody is interested, here the team behind Dex is following the whole process of SSO and MFA: https://github.com/dexidp/dex/issues/4560

<!-- gh-comment-id:3956985303 --> @adrianbaena commented on GitHub (Feb 25, 2026): If anybody is interested, here the team behind Dex is following the whole process of SSO and MFA: https://github.com/dexidp/dex/issues/4560
Author
Owner

@stelle007 commented on GitHub (Mar 16, 2026):

MFA was included when you used Zentinal for the quick deploymend. why did you make the product worse for self-hosted setup and remove MFA ?

This is a must have.

+1

<!-- gh-comment-id:4070805878 --> @stelle007 commented on GitHub (Mar 16, 2026): MFA was included when you used Zentinal for the quick deploymend. why did you make the product worse for self-hosted setup and remove MFA ? This is a must have. +1
Author
Owner

@hyllm commented on GitHub (Mar 18, 2026):

+1 ... also using Google as IdP for Owner and no local admin for now

<!-- gh-comment-id:4080909753 --> @hyllm commented on GitHub (Mar 18, 2026): +1 ... also using Google as IdP for Owner and no local admin for now
Author
Owner

@svenkispert commented on GitHub (Mar 21, 2026):

It's merged! :) Will be included in the upcoming release.

https://github.com/dexidp/dex/pull/3712

My guess is Netbird is waiting on Dex to add 2FA support before it will add that functionality to local user management without having to use a 3rd party / external IdP provider. I found this thread tracking the progress of adding 2FA to Dex if anyone is interested in following the progress:

dexidp/dex#3712

<!-- gh-comment-id:4104222207 --> @svenkispert commented on GitHub (Mar 21, 2026): It's merged! :) Will be included in the upcoming release. https://github.com/dexidp/dex/pull/3712 > My guess is Netbird is waiting on Dex to add 2FA support before it will add that functionality to local user management without having to use a 3rd party / external IdP provider. I found this thread tracking the progress of adding 2FA to Dex if anyone is interested in following the progress: > > [dexidp/dex#3712](https://github.com/dexidp/dex/pull/3712)
Author
Owner

@IngwiePhoenix commented on GitHub (Mar 29, 2026):

Came across this too and found this article here: https://netbird.io/knowledge-hub/accessible-mfa-implementation

Just installed NetBird myself and was confused to not find any MFA. This is very cruicial.

<!-- gh-comment-id:4150937858 --> @IngwiePhoenix commented on GitHub (Mar 29, 2026): Came across this too and found this article here: https://netbird.io/knowledge-hub/accessible-mfa-implementation Just installed NetBird myself and was confused to not find any MFA. This is very cruicial.
Author
Owner

@zcj6758 commented on GitHub (May 4, 2026):

我刚安装了NetBird,需要内置idp启用双因素身份验证(MFA)功能。这非常重要

<!-- gh-comment-id:4372795528 --> @zcj6758 commented on GitHub (May 4, 2026): 我刚安装了NetBird,需要内置idp启用双因素身份验证(MFA)功能。这非常重要
Author
Owner

@jnfrati commented on GitHub (May 4, 2026):

Hey hey! We're looking to release the MFA functionality in the next week or so, sorry for keeping y'all waiting!

We're trying to polish some rough edges but hopefully we can get this functionality out soon 🙌

In case anyone wants to keep an eye on the PRs:

<!-- gh-comment-id:4373288866 --> @jnfrati commented on GitHub (May 4, 2026): Hey hey! We're looking to release the MFA functionality in the next week or so, sorry for keeping y'all waiting! We're trying to polish some rough edges but hopefully we can get this functionality out soon 🙌 In case anyone wants to keep an eye on the PRs: - Management: https://github.com/netbirdio/netbird/pull/5804 - Dashboard: https://github.com/netbirdio/dashboard/pull/615
Author
Owner

@pkkrusty commented on GitHub (May 9, 2026):

Is this MFA limited to cloud SaaS offering, or will it exist in self-hosted?

<!-- gh-comment-id:4412315518 --> @pkkrusty commented on GitHub (May 9, 2026): Is this MFA limited to cloud SaaS offering, or will it exist in self-hosted?
Author
Owner

@Discolor3182 commented on GitHub (May 14, 2026):

It is added to 0.71.0. Thank you very much!

<!-- gh-comment-id:4453378276 --> @Discolor3182 commented on GitHub (May 14, 2026): It is added to 0.71.0. Thank you very much!
Author
Owner

@pkkrusty commented on GitHub (May 14, 2026):

Initial test seems to work great! Thank you for this important security feature!

<!-- gh-comment-id:4453965079 --> @pkkrusty commented on GitHub (May 14, 2026): Initial test seems to work great! Thank you for this important security feature!
Author
Owner

@sagehou commented on GitHub (May 14, 2026):

Thanks for your great work!
In addition to MFA barcode scanning, it would be even better to provide a way to easily copy the key~

<!-- gh-comment-id:4455982788 --> @sagehou commented on GitHub (May 14, 2026): Thanks for your great work! In addition to MFA barcode scanning, it would be even better to provide a way to easily copy the key~
Sign in to join this conversation.
No Label feature-request
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: DYNR/netbird#9877