Skip to content

Mideye+ App Touch Accept Setup for Server 4

Want to enable push notification MFA for your users? This guide explains how to install and configure the Mideye+ mobile app for iOS and Android devices. Users can receive OTP codes via push notification, use Touch Accept for one-tap authentication approval, or generate offline OTP codes when no network is available.

FeatureRequires NetworkUser Action
Push OTPYes (data)Enter code
Touch AcceptYes (data)Tap Accept/Deny
Offline OTPNoManual challenge signing

The Mideye+ app provides an alternative to SMS-based OTP delivery. It works over data networks (Wi-Fi or mobile data) instead of SMS, making it ideal for users who travel internationally or have poor cellular coverage. There is no additional charge for using Mideye+.


The following section will describe how to download and activate the Mideye+ app.

Mideye+ can be downloaded for both Android and iPhone users. For iPhone users, download the app here or by searching for Mideye+ directly in the App Store. iOS 9.0 or later is required.

Android users can download the Mideye+ app here or search for it directly in Google Play.

Once downloaded and installed, open the Mideye+ app. First time opening the Mideye+ app, the message “Mideye+ Would Like to Send You Notification” pops up. Click “Allow” to allow the app to send notifications each time an authentication attempt is made.

The activation consists of 3 steps:

  • Enter the phone number in international format e.g +46735084555 and press “Next” in the top right corner.

Enter the phone number in international format.

Mideye+ app iPhone screen prompting user to enter phone number in international format

  • Make an authentication attempt to the corporate resource (e.g Anyconnect, Citrix-portal etc) that is protected with Mideye.

Logon to a resource protected by Mideye.

Cisco AnyConnect VPN login screen showing username and password fields for MFA authentication

  • Once the SMS is received, open the message and click the link. A redirect to the Mideye+ app will take place with the text “Mideye+ activated”.

Click the link in the SMS

iPhone SMS message containing Mideye activation link for the Mideye+ app

Mideye+ is now activated

Mideye+ app showing successful activation confirmation message on iPhone

Once downloaded and installed, open the Mideye+ app. First time opening the Mideye+, the app will ask for permissions. Make sure to click “Allow” to allow the app to send notifications each time an authentication attempt is made.

Allow Mideye+ to make and manage phone calls

Android permission dialog requesting phone call access for Mideye+ app

Allow Mideye+ to send and view SMS messages

Android permission dialog requesting SMS access for Mideye+ app activation

Agree to terms

Mideye+ app terms and conditions acceptance screen on Android

The activation consists of 2 steps:

  • Enter the phone number in international format e.g +46701234567 and press “Next”.

Enter phone number in international format

Mideye+ app Android screen for entering phone number in international format

Start the activation of the app

Mideye+ app Android activation screen with Next button to begin setup

  • Make an authentication attempt to the corporate resource (e.g Anyconnect, Citrix-portal etc) that is protected with Mideye.

Logon to a resource protected by Mideye.

VPN login screen on Android device for authenticating with Mideye MFA

  • Once the text message is received the activation of Mideye+ will automatically finish.

Mideye+ is now activated

Mideye+ app showing successful activation message on Android device


When Mideye+ is activated, the app can be used to authenticate when logging on to a protected resource that is using Mideye two-factor authentication. Instead of receiving traditional text-messages containing an OTP, Mideye will send the OTP using data traffic and the OTP will be presented in the phone as a notification.

Mideye+ OTP notification

iPhone push notification showing Mideye OTP code for MFA authentication

Sending data OTP instead of traditional text messages have a big advantage when end-users do not have any network coverage, but still have internet access.

Mideye+ also works as a token card and can be used when both network coverage and internet access is missing. When end users try to authenticate, and the phone does not have any coverage, Mideye will instead present the user with the message “Phone not reachable, please sign xxxxxx”.

The message presented to the end-user when logging on lacking coverage. In this example, Cisco Anyconnect.

Cisco AnyConnect showing offline challenge message when phone has no network coverage

To sign, open the Mideye+ app and click “Manual signature at the bottom of the screen”

Enter the challenge and click sign.

Mideye+ app manual signature screen for offline OTP generation

Enter the OTP generated in the Mideye+ app at the login site.

Enter the OTP presented in the Mideye+

Mideye+ app displaying generated OTP code for offline authentication


If manual signing does not work, but instead the end-user is presented with a failed authentication, it is likely because the RADIUS timeout of the RADIUS client is set to less than 35 seconds. Refer to the section “Troubleshooting RADIUS client” in the Configuration guide.

User is not receiving any notifications when using Mideye+

Section titled “User is not receiving any notifications when using Mideye+”

For Mideye+ to function correctly it is important that the end-user accepts that Mideye+ can present notifications. This question is presented to the end-user only once after installing the app. If the user accidentally pressed “Deny” instead of “Allow”, no notifications with OTP will be shown during authentication. To manually fix this follow the instructions below:

  1. Tap the “Settings” icon.
  2. Scroll down and tap “Notifications”
  3. Tap Mideye+ in the “Notification style”
  4. Enable “Allow Notifications”

Enable notifications

iPhone Settings showing how to enable notifications for Mideye+ app

Enabling notifications vary depending on what version of Android is being used. Refer to each manufacturer’s manual for details.

Android is not presenting any notifications while the phone is in battery saving mode

Section titled “Android is not presenting any notifications while the phone is in battery saving mode”

If the phone is low on battery and the end-user enables battery saving mode, Mideye+ must be excluded to still be able to present notifications when authenticating. The example below shows how to achieve this using a Samsung phone. For other phones, refer to the manual from the manufacturer.

  1. Open “Settings”
  2. Open “Battery” and navigate to “Unmonitored Apps”
  3. Click “Add apps” and select Mideye+ followed by “Done”

Add Mideye+ to unmonitored apps

Samsung Android battery settings showing Mideye+ added to unmonitored apps list


To further ease the authentication process, Touch Accept can be used to simply allow or deny an authentication attempt. This function can be enabled from the Mideye configuration tool and does only affect those users that have Mideye+ installed on their cellphones. Also, Touch Accept does not use challenge-response when authenticating, which enables two-factor authentication on applications and services that do not have support for traditional two-factor authentication.

Open the Mideye configuration tool and navigate to “LDAP Servers”. Select the LDAP-server that is being used, and click modify. Select the tab “Authentication” and change the “Default authentication type” to 6, 7 or 8 depending if there should be a fallback available to traditional OTP. Fallbacks are only efficient if the authentication service supports challenge-response. In those cases, if for any reason Touch accept would fail, a normal OTP will be sent to the phone. If the authentication service does not have any support for challenge-response, authentication type 6 will be the only option.

Change the authentication type to 6, 7 or 8 to enable Touch Accept.

Mideye Configuration Tool LDAP authentication tab showing Touch Accept authentication type settings

Click “Save” followed by “Close” to restart the services.

To verify if the configuration is working, simply perform an authentication attempt to any Mideye enabled service. Now, instead of receiving an OTP to the Mideye+ app, a question to allow or deny the login will be presented. Since authentication type 8 (Touch-mobile) was selected in the previous step, an OTP will be sent if Touch should fail.

Login using Touch Accept.

Mideye+ app Touch Accept screen with Accept and Deny buttons for one-tap MFA approval