Skip to main content
Version: v2.18.x

(Recommended) Addressing authentication requirements

(Recommended) Addressing authentication requirements

The following features are not required, but are recommended with additional prerequisites.

Roles required: security administrator

Multi-Factor Authentication (MFA)

Multi-factor authentication (MFA) is supported for several Zowe components, including the Zowe Desktop, API Mediation Layer, and Zowe Application Framework. Multi-factor authentication is provided by third-party products with which Zowe is compatible. The following MFA products are known to work with Zowe:

To support the multi-factor authentication, it is necessary to apply z/OSMF APAR PH39582.

For information about using MFA in Zowe Application Framework, see Application Framework Multi-Factor Authentication.

important

Multi-factor authentication requires configuration with Single-Sign-On (SSO). Ensure that SSO is configured before you use MFA in Zowe.

Single Sign On (SSO)

Zowe has an SSO scheme with the goal that each time you use multiple Zowe components you should only be prompted to login once.

Requirements:

  • IBM z/OS Management Facility (z/OSMF)

For more information about single sign on (SSO), see Zowe API Mediation Layer Single Sign On Overview.

API Mediation Layer OIDC Authentication

Zowe requires ACF2 APAR LU01316 to be applied when using the ACF2 security manager.

For more information about OIDC authentication, see Zowe API Mediation Layer OIDC Authentication.