To configure authentication servers to use time-based one-time passwords
In the AMC, navigate to System Configuration > Authentication Servers.
In the Other Servers section, click Edit next to Configure time-based one-time password (TOTP) settings.
Click Configure.
Click Enable time-based one-time passwords.
Adjust the value in the Time difference field to adjust the time difference (in minutes) allowed between the clock on the client device and on the SMA appliance.
Set the value of the Automatically unlock account after _ minutes field to specify the amount of time (in minutes) before user accounts will be automatically unlocked after being locked from too many unsuccessful login attempts. (This option is selected by default.)
The user account is not automatically set to an unlocked state. It will be unlocked the next time that the user tries to log in, if the number of minutes specified in this field have passed since their last unsuccessful login attempt.
If you do not want user accounts automatically unlocked, unselect this option.
Click Save.
When you enable the usage of Time-Based One-Time Passwords, it is recommended that you only allow end users to register their devices through the WorkPlace or Connect Tunnel applications.