<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question MFA Re-Login Behavior Issue after logout on ServiceNow Customer Portal in Community Central forum</title>
    <link>https://www.servicenow.com/community/community-central-forum/mfa-re-login-behavior-issue-after-logout-on-servicenow-customer/m-p/3486795#M6039</link>
    <description>&lt;P class=""&gt;&lt;SPAN&gt;Hello Team,&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;We have enabled user-based MFA for external customer users.&lt;BR /&gt;&lt;BR /&gt;Step-Up MFA Policy- Enforce MFA for non-SSO logins&lt;BR /&gt;&lt;BR /&gt;In the Multi-Factor Authentication properties, the following options are set to &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Yes&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P class=""&gt;&lt;SPAN&gt;Enable Email OTP for Multi-Factor Authentication&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class=""&gt;&lt;SPAN&gt;Enable enhanced MFA setup UI to allow users to configure factors independently&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P class=""&gt;&lt;SPAN&gt;During testing in the Dev environment, the test user is prompted to configure MFA using both &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Authenticator App&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; and &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Email OTP&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;, and login works successfully with either method.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;However, after the user logs out of the customer portal and attempts to log in again, the following message is displayed for both methods:&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;&lt;EM&gt;“Your account requires Multi-factor authentication. Please enter the 6-digit code generated by the authenticator app on your mobile device.”&lt;BR /&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/STRONG&gt;Screenshot is also attached&amp;nbsp;for your reference.&lt;STRONG&gt;&lt;EM&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;Even when MFA is unchecked on the user record, and all entries are deleted from &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;User Multifactor Authentications&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;, the user is again prompted to set up MFA with both App and Email on next login — but the same message appears after logout and re-login.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;This behavior is consistent:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P class=""&gt;&lt;SPAN&gt;In a fresh browser window&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class=""&gt;&lt;SPAN&gt;In a different browser&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;Note&lt;/STRONG&gt;: Email OTP is retrieved from logs, as email sending is restricted in the Dev environment.&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P class=""&gt;&lt;SPAN&gt;Could you please review and advise on this MFA login behavior and suggest if we missed anything or any change required in MFA Policy?&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Best regards,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Ajay Bonsray&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 11 Feb 2026 12:06:14 GMT</pubDate>
    <dc:creator>ajaybonsray</dc:creator>
    <dc:date>2026-02-11T12:06:14Z</dc:date>
    <item>
      <title>MFA Re-Login Behavior Issue after logout on ServiceNow Customer Portal</title>
      <link>https://www.servicenow.com/community/community-central-forum/mfa-re-login-behavior-issue-after-logout-on-servicenow-customer/m-p/3486795#M6039</link>
      <description>&lt;P class=""&gt;&lt;SPAN&gt;Hello Team,&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;We have enabled user-based MFA for external customer users.&lt;BR /&gt;&lt;BR /&gt;Step-Up MFA Policy- Enforce MFA for non-SSO logins&lt;BR /&gt;&lt;BR /&gt;In the Multi-Factor Authentication properties, the following options are set to &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Yes&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P class=""&gt;&lt;SPAN&gt;Enable Email OTP for Multi-Factor Authentication&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class=""&gt;&lt;SPAN&gt;Enable enhanced MFA setup UI to allow users to configure factors independently&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P class=""&gt;&lt;SPAN&gt;During testing in the Dev environment, the test user is prompted to configure MFA using both &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Authenticator App&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; and &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Email OTP&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;, and login works successfully with either method.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;However, after the user logs out of the customer portal and attempts to log in again, the following message is displayed for both methods:&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;&lt;EM&gt;“Your account requires Multi-factor authentication. Please enter the 6-digit code generated by the authenticator app on your mobile device.”&lt;BR /&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/STRONG&gt;Screenshot is also attached&amp;nbsp;for your reference.&lt;STRONG&gt;&lt;EM&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;Even when MFA is unchecked on the user record, and all entries are deleted from &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;User Multifactor Authentications&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;, the user is again prompted to set up MFA with both App and Email on next login — but the same message appears after logout and re-login.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;This behavior is consistent:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P class=""&gt;&lt;SPAN&gt;In a fresh browser window&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class=""&gt;&lt;SPAN&gt;In a different browser&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;Note&lt;/STRONG&gt;: Email OTP is retrieved from logs, as email sending is restricted in the Dev environment.&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P class=""&gt;&lt;SPAN&gt;Could you please review and advise on this MFA login behavior and suggest if we missed anything or any change required in MFA Policy?&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Best regards,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Ajay Bonsray&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Feb 2026 12:06:14 GMT</pubDate>
      <guid>https://www.servicenow.com/community/community-central-forum/mfa-re-login-behavior-issue-after-logout-on-servicenow-customer/m-p/3486795#M6039</guid>
      <dc:creator>ajaybonsray</dc:creator>
      <dc:date>2026-02-11T12:06:14Z</dc:date>
    </item>
  </channel>
</rss>

