Enroll Remote Users in MFA

This page explains how multi-factor authentication (MFA) registration is triggered for remote users, depending on the type of session they open.

Published October 7, 2025

Overview

Remote users can enroll in MFA through different UserLock components. The appropriate method depends on how users connect to your environment (via VPN, IIS web apps, Remote Desktop Gateway, or UserLock Anywhere).

Session type

Enrollment trigger

Workstation from outside (UserLock Anywhere)

At Windows logon outside the corporate network

IIS

When accessing an IIS web app for the first time

Terminal from outside (RD Gateway)

When starting an RDP session through RD Gateway

Workstation with VPN connection

When unlocking the session during an active VPN connection

UserLock VPN Connect

When opening a VPN session via the UserLock VPN Connect

1. Workstation session from outside

Trigger

When the user logs on to Windows outside the corporate network, the Desktop agent can reach the UserLock service directly via the public Anywhere URL.
The MFA enrollment dialog appears if the account is not yet enrolled.

Typical workflow

  1. Administrator enables MFA for the account.

  2. User signs in to Windows from outside the network.

  3. The MFA enrollment dialog appears and completes automatically.

Requirements

  • Desktop Agent installed on the workstation.

  • UserLock Anywhere configured with a public URL.

  • Internet connection available.

Configuration

Available enrollment methods

2. IIS session

Trigger

When the user accesses a web application protected by IIS MFA, the enrollment prompt appears during the first connection if the account is not yet enrolled.

Typical workflow

  1. Administrator enables MFA for the account

  2. User opens the web application

  3. MFA enrollment is displayed and completed in the browser

Requirements

  • IIS integration with UserLock

  • Browser access to the web application

Configuration

Available enrollment methods

3. Terminal session from outside

Trigger

When the user connects to a Remote Desktop session through RD Gateway, the enrollment prompt appears if MFA enrollment is pending.

Typical workflow

  1. Administrator enables MFA for the account

  2. User connects via RD Gateway

  3. MFA enrollment is displayed during session logon

Requirements

  • UserLock integration with RD Gateway

  • RDP access through the gateway

Configuration

Available enrollment methods

4. VPN Session (Lock/Unlock method)

Trigger

On a corporate laptop with the Desktop Agent installed, if MFA is not yet enrolled, the prompt appears when the user unlocks the workstation during an active VPN connection.

Typical workflow

  1. The user takes the work laptop offsite.

  2. User connects the VPN.

  3. Administrator enables MFA for the account.

  4. The user locks and unlocks the session, the unlock triggers MFA enrollment.

Requirements

  • Desktop Agent installed

  • VPN tunnel connected to the corporate network

  • Local desktop session (not RDP)

Configuration

Available enrollment methods

5. UserLock VPN Connect

Trigger

When users connect via UserLock VPN Connect, the system redirects them to a browser window to complete MFA enrollment if required.

Typical workflow

  1. Administrator enables MFA for the account.

  2. User initiates the VPN connection via the UserLock VPN Connect.

  3. A browser window opens and guides MFA enrollment.

Requirements

  • UserLock VPN Connect properly configured.

  • Browser available during VPN connection setup.

Configuration

Available enrollment methods