ajouter dans le fichier : /etc/pam.d/sshd

auth required pam_google_authenticator.so nullok
**auth optional pam_succeed_if.so user ingroup sudo**
**auth optional pam_succeed_if.so user ingroup admin**

File: /etc/ssh/sshd_config

AuthenticationMethods publickey,keyboard-interactive
UsePAM yes
ChallengeResponseAuthentication yes