---
sourceDocument: Yokohama Platform security
sourceDocumentLink: https://www.servicenow.com/docs/r/yokohama/platform-security

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# MFA enforcement

# Multi-factor Authentication enforcement {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Enforcement of MFA for non-SSO logins to ServiceNow from the Yokohama release.

MFA enhances security by requiring users to provide two or more evidence to prove their identity during login. MFA protects accounts from threats like phishing and account takeovers.

MFA being a critical security tool against various identity takeover-related attacks. ServiceNow enforces MFA by default post-Yokohama upgrade and making it mandatory for non-SSO log ins (users performing login with only username and password or LDAP based authentication) to ensure a better
security posture and reduce the risk of breaches.

MFA enforcement is carried though a MFA policy that is activated by default from Yokohama or upgrade to Yokohama. The MFA is enforced the Enforce MFA for non-SSO logins policy is <kbd class="ph userinput">Active</kbd>
and honored through the MFA Context.  
Note:  
* The policy is enabled for all non-snc_external users performing local (username and password) or LDAP based authentication.
* The instance admin can modify the enforcement scope by changing the MFA context policy, policy criteria, or policy conditions.
{#mfa-enforcement__ul_csj_3v3_jdc}

Here's more details about MFA enforcement:

* Enforced to all production and non-production instances.
* Enforced to all the non-snc_external users and non-SSO login.
* Integration with Basic auth and OAuth resource owner password credential grant does not require MFA from Yokohama.

{#mfa-enforcement__ul_mgl_1bq_vcc}

To know more about the changes due to enforcement, see [Changes due to the MFA enforcement](https://www.servicenow.com/docs/X~Yg1jgEeRTebpj9Zo1wPg "Information about the changes that are expected due to the MFA enforcement.").

To know more about MFA, see [Exploring Multi-factor authentication](https://www.servicenow.com/docs/WP5AWYOu3fNRSyxIw5OBlw "Multi-factor Authentication (MFA) is an authentication method that requires users to provide information other than their basic credentials.").
**Related concepts**   

* [Configure Multi-factor authentication](https://www.servicenow.com/docs/VLCzC_XEsjEM1f4qpFIfkQ "Configure multi-factor authentication (MFA) to improve your users security posture when using ServiceNow.")
* [Using Multi-factor authentication](https://www.servicenow.com/docs/FrBhtPob8yJDmyzCSqJFXg "Learn how to use multi-factor authentication tools to securely access your instance.")
* [MFA enforcement properties](https://www.servicenow.com/docs/zfDw4s8l1~IigFGNc2Zluw "Configure the properties for MFA enforcement from Yokohama and upgrade to Yokohama.")
* [Troubleshooting MFA enforcement](https://www.servicenow.com/docs/9AHed8taUyXXJcPP3eXXmA "Troubleshooting information due to the MFA enforcement.")
* [Frequently asked questions - MFA enforcement](https://www.servicenow.com/docs/zoF3VQoRlegokwSpnBCO9A "Details about some of the FAQs due the MFA enforcement.")

