| 01Multiple Authentication Methods |
Supports different verification factors such as authenticator apps, push approvals, one-time passcodes, biometrics, hardware tokens, and security keys. |
User Enters Primary Credential→
Select / Trigger Second Factor→
Verify Authentication Factor→
Grant Access
|
Authenticator app, push, OTP, biometric, and hardware-key support
Phishing-resistant methods such as FIDO2 / WebAuthn
Ability to enable or restrict methods by user or application
|
| 02Push-Based Authentication |
Sends login approval requests to a registered mobile device so users can approve or deny access without manually entering a code. |
User Attempts Login→
Send Mobile Push Request→
User Approves / Denies→
Complete Authentication
|
Number matching or other anti-push-fatigue protections
Device, location, and application context shown to users
Fallback methods when push notifications are unavailable
|
| 03One-Time Password & Token Authentication |
Generates temporary authentication codes through software tokens, hardware tokens, SMS, email, or other supported channels. |
Trigger OTP Challenge→
Generate / Deliver Code→
User Enters OTP→
Validate & Continue Login
|
TOTP, HOTP, hardware token, SMS, and email options
Code expiration, retry limits, and replay protection
Security controls for weaker channels such as SMS
|
| 04Risk-Based & Adaptive Authentication |
Adjusts authentication requirements according to contextual risk signals such as device, location, network, behavior, or sensitivity of the requested resource. |
Evaluate Login Context→
Calculate Access Risk→
Apply Normal / Step-Up MFA→
Allow, Challenge or Block
|
Device, IP, location, impossible-travel, and behavior signals
Configurable risk thresholds and step-up rules
Clear administrator visibility into authentication decisions
|
| 05Passwordless & Phishing-Resistant Authentication |
Uses possession-based or biometric credentials such as passkeys and security keys to reduce dependence on passwords and resist credential phishing. |
Register Trusted Credential→
User Initiates Login→
Verify Device / Biometric Credential→
Authenticate without Password
|
FIDO2, WebAuthn, passkey, and hardware security-key support
Platform and roaming authenticator compatibility
Migration path from password-based MFA to passwordless access
|
| 06Device Registration & Trusted Device Management |
Registers devices used for authentication and lets administrators control trusted endpoints, device changes, enrollment status, and authentication eligibility. |
User Enrolls Device→
Verify Device Ownership→
Register Trusted Authenticator→
Monitor / Revoke when Needed
|
Secure device enrollment and re-enrollment processes
Device inventory, status, and authentication-method visibility
Remote revocation for lost, stolen, or retired devices
|
| 07MFA Policies & Conditional Access |
Defines when MFA is required based on users, groups, applications, networks, devices, roles, or access conditions. |
Create Access Policy→
User Requests Resource→
Evaluate Policy Conditions→
Require, Bypass or Block MFA
|
Policies by user, group, app, device, network, and role
Step-up MFA for sensitive applications or privileged actions
Exceptions, trusted locations, and bypass controls with auditability
|
| 08Self-Service Enrollment & Account Recovery |
Lets users register authentication factors, add backup methods, replace devices, and recover access with less help-desk involvement. |
User Opens Security Portal→
Verify Existing Identity→
Add / Replace Authentication Factor→
Resume Secure Access
|
Self-service device and factor enrollment
Secure recovery and lost-device replacement workflows
Backup factors without creating weak recovery paths
|
| 09Authentication Monitoring & Threat Detection |
Tracks authentication attempts, failures, denied pushes, suspicious access patterns, and administrative changes to help identify compromised accounts or misuse. |
Collect Authentication Events→
Analyze Login Activity→
Detect Suspicious Pattern→
Alert / Block / Investigate
|
Successful, failed, denied, and bypassed authentication logs
Alerts for unusual failures, push abuse, and risky access
Export or integration with SIEM and security monitoring tools
|
| 10MFA Integrations & Authentication Reporting |
Connects MFA with identity providers, directories, cloud applications, VPNs, infrastructure, and business systems while reporting authentication adoption and security activity. |
Connect Identity & Applications→
Enforce MFA across Resources→
Aggregate Authentication Data→
Review Security & Adoption
|
SAML, OIDC, RADIUS, LDAP, APIs, and required application integrations
MFA enrollment, usage, failure, and policy-compliance reporting
Integration with IAM, SSO, VPN, cloud, SIEM, and endpoint platforms
|