Enabling MFA
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-05-2024 09:06 PM
Hello team,
My customer is planning to enable MFA - EMail(mandatory) and AUthenticator (optional) for users.
My question is
1. If users enable authenticator , can they still receive the one time code via email even if Authenticator is default one . Can they choose between two ?
2. Can users reset Autheticator validation as a self service ? or it has to be always system administrator?
Thanks.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-05-2024 09:43 PM
-
Options for Receiving One-Time Codes: Typically, if users have enabled authenticator as an optional factor, they should still be able to receive one-time codes via email, especially if email is set as a mandatory factor. Users may have the option to choose between receiving the one-time code via email or using their authenticator app. However, this specific configuration might depend on how MFA is implemented and configured in your ServiceNow instance. It's advisable to check the specific settings and configurations within your ServiceNow environment to confirm this behavior.
-
Self-Service Reset for Authenticator Validation: Whether users can reset authenticator validation as a self-service action or if it requires system administrator intervention depends on the configuration and policies set up in your ServiceNow instance. ServiceNow typically provides flexibility in configuring self-service options for users, including resetting MFA factors like authenticator validation. This can usually be configured based on your organization's security policies and requirements. You can check the ServiceNow documentation or consult with your ServiceNow administrator to understand how self-service reset for authenticator validation can be configured in your environment.
For both questions, it's essential to review your organization's specific configurations and policies within ServiceNow, as these capabilities can be tailored to meet your organization's security and usability needs.
Mark it Helpful and Accept Solution !! If this helps you to understand.

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-06-2024 02:46 AM
Hi @SGS1 ,
The answer to both of your questions is Yes.
- Users get both options after configuring the authenticator app. They can choose the option on the MFA validation screen.
- Yes, users can log in with email OTP-based MFA and navigate to their user profile section to reset the authenticator app.
Thanks,
Randheer