SonarQube itself does not handle Multi-factor Authentication (MFA) when using delegated authentication methods like Microsoft AD or SAML.
Instead, MFA must be managed by the external identity provider you integrate with—such as Microsoft AD FS or your SAML provider.
If your Microsoft AD environment enforces MFA, it will automatically apply when users log in to SonarQube. Therefore, configure and enforce MFA on your AD or SAML solution, and SonarQube will respect those security measures during authentication.
Only the latest version of SonarQube Community Build is considered active, so you’ll need to upgrade and see if the situation is still replicable before we can help you.