- Products
- Learn
- Local User Groups
- Partners
- More
Step Into the Future of
AI-Powered Cyber Security
The State of Ransomware Q1 2026
Key Trends and Their Impact
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
CheckMates Go:
CheckMates Fest
Configuring MFA is something essential nowadays, and its setup should be intuitive. When I tried to find where to configure the email string for SMTP Relay, I noticed that in SmartConsole R82 it is extremely hidden, and placed in a section that, in my opinion, does not make much sense. It should be simpler and ideally located within the Gateway properties under Authentication > Dynamic ID.
Below, I’ll show where this configuration is located. This can serve as a useful reference for others trying to configure it, and also as a suggestion for the Check Point team to improve this in future SmartConsole versions, making MFA settings more intuitive.
The “SMS provider and email” option is locked under DynamicID Settings. Below I will show where this configuration is located.
Go to “Manage & Settings” > Blades > Mobile Access > Capsule Workspace Settings
NOTE: In my opinion, it does not make sense for this configuration to be so hidden, especially within Capsule Workspace settings, which are expected to be deprecated.
Go to “Multiple Authentication”
In the “Client Authentication” window > DynamicID Settings, enable the option:
“Challenge users to provide the DynamicID one-time password sent to their email account or mobile device via SMS”
Add the SMTP information string in the “SMS provider and email” field.
NOTE:
Regarding this string, it is important to validate the following SMTP information:
For email-based multi-factor authentication, you will need the following SMTP details:
Example:
smtp.office365.com
You need to determine:
Key question:
Does the SMTP server require a username and password?
If the SMTP server does not require authentication, you can use a string similar to the example below:
mail:TO=$EMAIL;SMTPSERVER=system.mail.com;FROM=no-reply@domain.com;BODY=$RAWMESSAGE
There is an older SK that can be used as a reference:
"sk144712 - How to enable SMTP authentication or TLS-SMTP for DynamicID", which mentions that:
"Dynamic ID with an SMTP server that requires username and password for authentication is supported."
Then go back to the Security Gateway or Cluster properties, navigate to VPN Clients or Mobile Access > Authentication, and configure Multiple Login Options, adding the first option and then DynamicID as the second.
Edit DynamicID as shown below if you want to use "Send Email" only.
Configure the “User Directories”
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY