OpenVPN - Enroll in MFA using Microsoft Authenticator
The following guide will walk through registering a Multi-factor authentication token for accessing the C2 Education VPN. At C2 Education, we primarily use the Microsoft Authenticator app for Android and Apple devices.
Enroll from the Client Web
- Begin by signing in to https://vpnas.c2educate.com using firstname.lastname and your network password
- Upon login to the website, the prompt below displays the MFA shared key in QR code and plaintext format
-
From your mobile device, open the Microsoft Authenticator app, select the + in the upper right, and then select Other account (Google, Facebook, etc.).
For more information about Microsoft Authenticator: https://www.microsoft.com/en-us/security/mobile-authenticator-app

-
When prompted, use your device's camera to scan the QR code shown on your computer screen.
Note: If your camera isn't working properly, you can enter the key displayed below the QR code

- Once the scan completes, you must enter the six-digit code provided in Microsoft Authenticator.
Access the code in Authenticator by locating the line titled OpenVPN. If the code is not shown, tap the > symbol to access the code.


- Click Confirm Code.
Updated Login Experience
Once the registration is complete, return to the VPN client installed on your computer an login to the VPN as you normally would
- Enter your network password
- The next prompt is for the Authenticator Code
- To get the code, open the Authenticator app on your mobile device
- Locate the line for OpenVPN and note the code (changes every 30 seconds)
- If the code is not displayed, tap the line for OpenVPN to access the code
- Enter the code on the computer before it changes on your phone and click Send
- The VPN should now be connected
Indicators that you need to register for MFA
If is MFA is enabled for your account, but you have not yet registered, you will receive the following prompt. Follow the steps above to register.
Authentication Failed
You must enroll this user in Authenticator first before you are allowed to retrieve a connection profile.
