Customers have installed this add-on in at least 32 active instances.
    by syracom consulting AGfor JIRA Server 7.0.0 - 7.2.3 and more versions
    Versions available for JIRA Server 6.2.5 - 6.4.14
    This add-on isn't formally supported, but you can ask a question via Atlassian Answers.

    Ask a question

    syracom consulting AG supports this add-on.

    Get support

    Strong Security via 2-factor authentication: efficient but user friendly

    Strong Security via 2-factor authentication: efficient but user friendly

    Strong Security

    Seamless Integration

    Support of different mobil authenticators

    Ensure limited access for authorized persons only via enhanced security: in addition to the username and password, a registered mobile device will be used each login time to generate a PIN code valid for half a minute.

    Based on Atlassian plugin system 2, just install this add-on via Marketplace like others behind the firewall: you do not have to patch anything nor does the add-on needs to communicate to any third-party system.

    Based on RFC 6238 the add-on supports different authenticator apps. You decide which authenticator fits your needs and infrastructure. Free authenticators are available for iOS, Android, WindowsPhone and BlackBerry.

    More details

    The default login for Atlassian tools is based on username and password: this is not a strong authentication as both values can be easily passed/copied to other persons using them in parallel to the owner. A secure login depends on multiple aspects and combine e.g. knowledge with physical gadgets, which cannot be duplicated that easily. If the gadget will be stolen, it is useless without the knowledge aspect. One sample of such a secure login is a 2-factor authentication using user name/password and a mobile device as key code generator resp. authenticator.

    ATTENTION: a mobile authenticator is not a barcode reader!

    To use strong security, the SYRACOM add-on has to be installed and activated as described in our Administrator's Guide. Furthermore you must have an authenticator app installed on your mobile device. You can use every app which is compliant to the RFC 6238 standard. Please read the Users Guide having listed examples for different mobile phones and operation systems!

    User reviews

    Sign in to write a review »
    by Philipp Gayret on 2016-10-19
    This plugin works fine if you know how to use it. A major issue with it is it only presents the QR code for setting up a user's 2 Factor authentication a single time, and then never again. Even if the user hasn't scanned the QR code and hasn't entered a pin, it won't be shown again to the user. Some users who aren't fully aware what the QR code is for will close the page, and then they're forced to enter a pin and no way to login. We have a fairly large organisation and this is causing a lot of extra work for our admins who have to manually reset QR codes for users. This application would be perfect if it was clearer to the user what the QR code is for, how to use the 2 factor authentication methods, and if QR code only disappeared after a PIN is entered successfully. If it had those features, this application is a no-brainer to install and I would recommend it to anyone using Jira.
    Was this review helpful?YesNo

    syracom consulting AG

    Dear Philipp,

    thank you for your honest and constructive feedback. It helps us to improve the quality of the plugin and to increase the user experience. We will look into your suggestions and see how to improve it. At the moment the plugin runs in kind of a "paranoid" mode from security perspective, activating the security tokens, the moment the QR code is generated, which leads to the behavior you are describing. But we have a few ideas, how to improve this, without loosing security.

    In Addition we are thinking about adding some kind of on boarding functionality, in order to describe unexperienced users, how 2 factor authentication is working and what to do with the QR code.

    Best regards,



    Pricing details are loading…

    Paid-via-Atlassian pricing FAQ

    How does server add-on pricing work?

    Server products and add-ons are hosted on your servers. Licenses are perpetual and the purchase price include 12 months of maintenance (support and version updates).

    You can renew maintenance after 12 months at 50% of the current purchase price. You can upgrade the tier of your host product and add-on licenses at any time. Upgrade prices are calculated based on Atlassian's formula (view example).

    If add-on pricing changes after your initial purchase, there's a 60-day grandfathering period during which you can renew based on the old pricing.

    How do I determine my server pricing tier?

    For JIRA Server 7.0 or later, the add-on tier should match the maximum tier of the licensed JIRA applications on your instance. For example, if you're running JIRA Software (50 users) and JIRA Service Desk (10 agents) on the same instance, you should purchase the 50-user tier for add-ons.

    For versions of JIRA Server prior to 7.0, the add-on tier should match the licensed user tier for JIRA. Even if fewer users want to use the add-on than your JIRA license, the two licenses should match exactly.

    Do you offer academic, community, or open-source licenses?

    For server add-ons, purchase and renewal is half-price if you have an academic license for your Atlassian host application. Server add-ons are always free for community and open-source licenses. Cloud add-ons do not have discounted or free licenses.

    For more details about qualifying for special licenses, see here.

    Can I extend my free trial?

    For server add-ons, you can extend your add-on trial up to 5 times - in other words, for up to six months. Extend your trial by generating a new evaluation license key from Atlassian Marketplace. Click Try it free and you'll be directed to generate a new license. Paste this license key into the add-on listing in UPM from your Atlassian host application, and you're all set.

    How can I buy add-ons for my legacy JIRA Server or Confluence Server license?

    If you own a legacy JIRA Server Unlimited (100+ users) or Confluence Server Unlimited (2000+ users) license purchased in 2012 or earlier, legacy add-on pricing is no longer available. You have two options for add-on purchasing:

    • Purchase the add-on at the non-legacy Unlimited (10000+ users) tier.
    • Renew your JIRA or Confluence license at a non-legacy tier, then purchase the add-on at the same tier.

    Learn more


    syracom consulting AG supports 2-Factor Auth Secure Login - JIRA. You can ask a support question via Atlassian Answers to get help.

    Ask a question


    Version 1.1 JIRA Server 7.0.0 - 7.2.3 Released 2016-10-04


    Support of JIRA groups and IP-ranges


    • Ability to configure black-/white-list of IP-ranges to force 2-factor authentication or not in order to distinguish between company-internal users and e.g. home-working users with high security.
    • Ability to configure black-/white-list of a JIRA group to just force members for 2-factor authentication e.g. for external users or to use 2FA for everybody but internals.


    1. Log into your JIRA instance as an admin.
    2. Click the admin dropdown and choose Atlassian Marketplace. The Manage add-ons screen loads.
    3. Click Find new add-ons from the left-hand side of the page.
    4. Locate 2-Factor Auth Secure Login - JIRA via search. The appropriate add-on version appears in the search results.
    5. Click Try free to begin a new trial or Buy now to purchase a license for 2-Factor Auth Secure Login - JIRA. You're prompted to log into MyAtlassian. 2-Factor Auth Secure Login - JIRA begins to download.
    6. Enter your information and click Generate license when redirected to MyAtlassian.
    7. Click Apply license. If you're using an older version of UPM, you can copy and paste the license into your JIRA instance.

    To find older 2-Factor Auth Secure Login - JIRA versions compatible with your instance, you can look through our version history page.

    Similar add-ons