An open-source plugin that allows XNAT administrators to enable and require multifactor authentication is now available to the XNAT community. Version 1.5.0 of the XNAT MFA Plugin, available now, is the first open-source release of this plugin functionality. Features include:
Support for Google Authenticator as the primary recommended MFA method
Fallback to OTP via email supported for users who have lost their MFA device
Robust administrative controls for managing individual users' MFA or site-wide preferences
The MFA plugin is known to be compatible with XNAT versions 1.8.10.5 and higher, but is likely compatible with earlier versions in the 1.8.x line.
Please see the MFA Plugin Documentation for further details on installing and using this plugin, as well as known issues in this release.
You can download this plugin now at xnat.org/downloads.