Multi-factor Authentication context
The Multi-factor Authentication (MFA) policy context uses a policy to define how and when MFA is enforced during the login process.
MFA context record
The MFA policy context defines whether your users must provide a second form of authentication when logging in. This context does not deny access to your instance as the post-authentication and pre-authentication policies. The policy you select in this context takes precedence over user or role-based configurations for multi-factor authentication.
To access the MFA context, navigate to .
Use the fields in the Post-authentication policy context record to define how your instance uses your policy.
- If the default policy is Step-Up MFA Policy, users will be shown with Multi-factor Authentication if policy configured in Step-Up MFA Policy evaluates to true. Policy takes precedence over the user or role based configuration.
- MFA with SSO login will only be available if glide.authenticate.mfa.with.multisso.enabled Property is set to true.
- You can navigate to the Authentication Policy record to Add or Edit the 'Policy Input(s)' to the referenced Policy field (Step-Up MFA Policy or Step-Down MFA Policy).
- MFA context policy applies only for user log ins. It does not apply for API authentication, basic auth, and OAuth resource owner password credential grant.
| Field | Description |
|---|---|
| Name | Name of the policy context. This field is static and cannot be changed. |
| Description | Description of the context |
| Default Policy | Defines the default behavior of this context when evaluating the policy. Select from
the following options.
|
| Step-Up MFA Policy | The policy used for this context uses. This field appears only when the Default Policy field is set to Step-Up MFA Policy. |
| Step-Down MFA Policy | The policy used for this context uses. This field appears only when the Default Policy field is set to Step-Down MFA Policy. |
Policy inputs and conditions
The Policy Input and Policy Conditions tabs
display the inputs and conditions of the policy selected in the Step-Up MFA
Policy or Step-Down MFA Policy field. These tabs serve as a
reference, but cannot be used to change the policy inputs or conditions. To modify your policy
settings, navigate to the policy using the reference icon () next to the Step-Up MFA Policy or Step-Down MFA
Policy field.
MFA factor policies
MFA factor policies are a critical component of an organization's security posture, enabling you to enforce additional verification steps beyond passwords. These policies define the authentication methods that users must employ to access providing a flexible and customizable approach to authentication. For more information, see Multi-Factor Authentication factor policies.