MFA Policies
MFA Policies control when additional verification is required during authentication.
Audience: Developers, CTOs
Read this page when hardening login policy for administrators or higher-risk users.
What This Feature Is For
Use MFA Policies to require stronger verification for privileged access, risky events, or tenant-wide security posture upgrades.
Workflow
- Open MFA Policies.
- Review the current enforcement scope.
- Create or edit a policy.
- Assign the policy to the target population.
- Validate the login flow in a controlled environment.
Working Example
Require MFA for all Admin Portal users while allowing lower-friction login for low-risk customer portals.
Common Pitfalls
- Enabling MFA broadly without validating delivery and recovery paths.
- Forgetting to test administrator break-glass access.
Troubleshooting Tips
- If users are stuck in MFA loops, inspect correlation IDs across the authentication and MFA logs.