Multi-factor authentication

Enrollment, supported factors, and resetting a user
Report issue

MFA adds a second proof of identity at login. This guide covers which factors CSI Auth supports, when a user is challenged, and how support staff reset a user who has lost their factor.

Supported factors

FactorNotes
Authenticator app (TOTP)Preferred for internal users
Push notificationRequires the Guardian app
SMSWeakest option; avoid for privileged accounts
Recovery codeIssued once at enrollment
WebAuthnPhishing resistant

When users are challenged

Enrollment

A user enrolls on first login after MFA is required for them. Recovery codes are shown once at enrollment and cannot be retrieved later.

Checking enrollment status

An authenticator record shows which factors a user has, and when each was enrolled.

Resetting a user

Removing a user’s enrollment lets them enroll again on their next login. It also removes the only proof that the person logging in is the account owner, so verify identity before doing it.

Enforcing MFA for administrators

Accounts that can change identity configuration should require a phishing-resistant factor.

Auditing

MFA enrollments, challenges, and resets appear in the tenant logs.

Troubleshooting

SymptomLikely cause
Codes are always rejectedDevice clock drift on the authenticator
No SMS receivedCarrier filtering or an unverified number
Prompted on every loginDevice trust not being remembered
Locked out with no factorNeeds an identity-verified reset