---
sourceDocument: Brazil Platform security
sourceDocumentLink: https://www.servicenow.com/docs/r/platform-security

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# MFA context

# Multi-factor Authentication context {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Multi-factor Authentication context

The Multi-factor Authentication (MFA) policy context in ServiceNow governs how and when MFA is enforced during user login.
It uses a policy-based approach to require users to provide a second form of authentication, enhancing security beyond just passwords.
This context is specifically for user logins and does not apply to API authentication, basic authentication, or OAuth resource owner password credential grants.
Show full answer Show less  
The MFA context policy takes precedence over any user- or role-based MFA configurations, ensuring consistent enforcement according to the configured policy. Access to the MFA context is through **All \> Multi-factor Authentication \> MFA Context**.

## Key Features

* **Policy-driven MFA enforcement:** You can configure the MFA context to use either a Step-Up MFA Policy or a Step-Down MFA Policy:
  * **Step-Up MFA Policy:** MFA is enforced only when specified policy conditions evaluate to true.
  * **Step-Down MFA Policy:** MFA is enforced by default and only bypassed when policy conditions evaluate to true.
* **Policy precedence:** The selected MFA context policy overrides user or role-based MFA settings.
* **Policy Inputs and Conditions:** The MFA context form displays inputs and conditions of the selected policy as reference. Actual editing must be done directly on the policy record.
* **SSO Integration:** MFA with Single Sign-On (SSO) is supported if the system property `glide.authenticate.mfa.with.multisso.enabled` is set to `true`.
* **Configuration Interface:** The MFA context form includes fields for naming the context, describing it, selecting the default policy type, and choosing the specific policy to apply.

## Practical Considerations for ServiceNow Customers

* Use the MFA context to centrally control MFA enforcement, ensuring consistent security policies across your instance.
* Choose between Step-Up and Step-Down policies depending on whether you want MFA enforced selectively or by default.
* Modify policy conditions directly on the policy record to customize when MFA is prompted during login.
* Enable MFA with SSO by setting the appropriate system property to true for seamless user experience.
* Understand that this context applies only to interactive user logins, so other authentication methods require separate controls.

## Key Outcomes

By configuring the MFA context, you can:

* Enhance security by enforcing multi-factor authentication based on flexible, policy-driven conditions.
* Ensure consistent MFA enforcement that overrides user or role exceptions.
* Integrate MFA seamlessly with SSO environments when enabled.
* Maintain clear visibility into the policies and conditions governing MFA enforcement through the MFA context form.  
The Multi-factor Authentication (MFA) policy context uses a policy to define how and when MFA is enforced during the login process.

## MFA context record {#mfa-auth-context__section_fmr_pds_2qb}

The MFA policy context defines whether your users must provide a second form of authentication when logging in. This context does not deny access to your instance as the post-authentication and pre-authentication policies. The
policy you select in this context takes precedence over user or role-based configurations for multi-factor authentication.

To access the MFA context, navigate to AllMulti-factor AuthenticationMFA Context.

Use the fields in the Post-authentication policy context record to define how your instance
uses your policy.  
Note:  
* If the default policy is Step-Up MFA Policy, users will be shown with Multi-factor Authentication if policy configured in Step-Up MFA Policy evaluates to true. Policy takes precedence over the user or role based configuration.
* MFA with SSO login will only be available if <kbd class="ph userinput">glide.authenticate.mfa.with.multisso.enabled</kbd> Property is set to true.
* You can navigate to the Authentication Policy record to Add or Edit the 'Policy Input(s)' to the referenced Policy field (Step-Up MFA Policy or Step-Down MFA Policy).
* MFA context policy applies only for user log ins. It does not apply for API authentication, basic auth, and OAuth resource owner password credential grant.
{#mfa-auth-context__ul_vtv_yyw_jrb}  
{#mfa-auth-context__table_otz_ngr_2qb__entry__2}

| Field | Description |
|-|-|
| Name | Name of the policy context. This field is static and cannot be changed. |
| Description | Description of the context |
| Default Policy | Defines the default behavior of this context when evaluating the policy. Select from the following options. Step-Up MFA Policy :   Enforces MFA to users when the policy conditions defined in the Step-Up MFA Policy field evaluate to true. Step-Down MFA Policy :   Enforces MFA by default. MFA is not enforced only when the policy conditions defined in the Step-Down MFA Policy field evaluate to true. |
| Step-Up MFA Policy | The policy used for this context uses. This field appears only when the Default Policy field is set to Step-Up MFA Policy. |
| Step-Down MFA Policy | The policy used for this context uses. This field appears only when the Default Policy field is set to Step-Down MFA Policy. |
[Table 1. MFA context form]

{#mfa-auth-context__table_otz_ngr_2qb}

## Policy inputs and conditions {#mfa-auth-context__section_uw4_vhr_2qb}

The Policy Input and Policy Conditions tabs
display the inputs and conditions of the policy selected in the Step-Up MFA Policy or Step-Down MFA Policy field. These tabs serve as a
reference, but cannot be used to change the policy inputs or conditions. To modify your policy
settings, navigate to the policy using the reference icon (![Reference icon]()) next to the Step-Up MFA Policy or Step-Down MFA Policy field.  
Note:  
Policy conditions can be created from here, but as a good practise it is recommended to add new policy conditions from policy page.  
This example shows an MFA context record configured using a step-up MFA policy. This default policy means that MFA is enforced only when the conditions defined in the policy evaluate to true. The context uses a policy called Step-Up MFA policy. That policy has a set of inputs and conditions that are displayed in the Policy Input and Policy Condition tabs.Figure 1. MFA policy context form

## MFA factor policies {#mfa-auth-context__section_qbk_xhx_bgc}

MFA factor policies are a critical component of an organization's security posture, enabling you to enforce additional verification steps beyond passwords. These policies define the authentication methods that users must employ
to access providing a flexible and customizable approach to authentication. For more information, see [Multi-Factor Authentication factor policies](https://www.servicenow.com/docs/A23~MepN0GfTXtaWV6j8rw "Use the MFA factor policies to specify the types of authentication factors that you would like to permit for your instance.").

*[\>]: and then


