Windows RDP · Reference

What are the different Multi Factor Authentication methods for RDP?

Four methods are available on any Spriv-protected RDP login. Here's how each one works and what it requires.

Allow / Deny

Requires user action on every login. A push notification displays the username, IP address and server name to help verify the attempt.

Requires: the Spriv app installed and paired, plus stable internet.

Two-Way SMS

An SMS is sent to the phone tied to the username; the user replies "Yes" or "No" to approve or deny. No app install required, and it works in over 200 countries.

Requires: reasonable mobile carrier reception weak reception can delay delivery. The "access from" location is determined by the computer's GeoIP. Unlike the other methods, Two-Way SMS carries an additional per-message charge.

TOTP

Generates a six-digit code from the phone's internal clock, with a 30-second time-to-live. Works with no internet or carrier reception, which makes it a good fallback while traveling.

To use: open the Spriv app, tap "TOTP" next to your paired username to view the current 6-digit code, then select "TOTP" at login and enter it in the field below "TOTP:".

Next: Logging in offline →
Was this helpful?