Multi-factor authentication
Multi-factor authentication
MFA adds a second proof of identity at login. This guide covers which factors CSI Auth supports, when a user is challenged, and how support staff reset a user who has lost their factor.
Supported factors
When users are challenged
Enrollment
A user enrolls on first login after MFA is required for them. Recovery codes are shown once at enrollment and cannot be retrieved later.
Checking enrollment status
An authenticator record shows which factors a user has, and when each was enrolled.
Resetting a user
Removing a user’s enrollment lets them enroll again on their next login. It also removes the only proof that the person logging in is the account owner, so verify identity before doing it.
Enforcing MFA for administrators
Accounts that can change identity configuration should require a phishing-resistant factor.
Auditing
MFA enrollments, challenges, and resets appear in the tenant logs.