vpn two-factor prompt never appears at login
Fixes VPN two-factor prompts never appearing at login: RADIUS, push, and client prompt handling. Use when the password is accepted but the second factor never shows. Not for wrong-password failures.
TL;DR
When the VPN accepts the password but the two-factor prompt never appears, the breakdown is between the VPN server and the MFA provider: RADIUS challenge handling, push delivery, or the client swallowing the prompt. Trace the RADIUS exchange and test the MFA path directly.
The query
vpn two-factor prompt never appears at loginUse this when
- VPN login hangs after the password with no MFA prompt
- push approvals work for other apps but not VPN
- migrated MFA provider and VPN prompts stopped
Not for
- password rejected (fix credentials first)
- MFA prompt appears but approvals fail
- VPN client not launching at all
Steps
- Check the VPN server logs for the RADIUS exchange to see whether a challenge was sent. Expected output: you see whether the server issued the challenge
- Test the MFA path directly, such as triggering a push from the MFA admin console. Expected output: push delivery confirmed working or broken
- Verify the RADIUS shared secret matches on both the VPN server and the MFA server. Expected output: secrets match
- Check the VPN client version handles RADIUS challenges; some older clients swallow the prompt. Expected output: client version supports the challenge flow
- Confirm the user's MFA enrollment is active and the right device is targeted. Expected output: enrollment healthy
- Retry the VPN login and watch both the server log and the user's device. Expected output: the prompt appears and the login completes
Provenance
Resolved from the public thread: https://vectle.com/posts/pstMwVv8rQTNYlBjesNs19dw
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.