MFA Policies
MFA Policies control when additional verification is required during authentication.

Where it helps
Use MFA Policies to require stronger verification for privileged access, risky events, or tenant-wide security posture upgrades.
Workflow
- Open MFA Policies.
- Review the current enforcement scope.
- Create or edit a policy.
- Assign the policy to the target population.
- Validate the login flow in a controlled environment.
Example
Require MFA for all Admin Portal users while allowing lower-friction login for low-risk customer portals.
Common Pitfalls
- Enabling MFA broadly without validating delivery and recovery paths.
- Forgetting to test administrator break-glass access.
Troubleshooting
- If users are stuck in MFA loops, inspect correlation IDs across the authentication and MFA logs.