Push notification MFA
Push notification multi-factor authentication (MFA) lets your customers approve sign-ins from your brand's mobile app instead of entering a passcode. When a login requires a second factor, Strivacity sends a push notification to the customer's enrolled device, and the customer approves or denies the request in the app.
You can enable and configure the method on the Multi-factor methods tab of your Adaptive Access policy.
Prerequisites
- A saved push notification configuration for Firebase Cloud Messaging (FCM HTTP v1), Apple Push Notification service (APNs), or both. The Push MFA method can't be enabled until one exists.
- A mobile app that integrates the Strivacity mobile SDK. See the mobile SDK push notification MFA guide.
Settings
- On the Multi-factor methods tab, enable Push MFA. Strivacity will send a push notification to a registered device for approval in the mobile app.
- Choose whether enrollment is Optional or Mandatory, just like any other MFA method.
- Set the Push notification approval lifetime. This is how long a customer has to answer the challenge before it expires. The default is 60 seconds.
- Optionally, select Require a registered FIDO authenticator to require customers to verify their identity with a FIDO authenticator registered on their mobile device before they can open the notification.
- Choose the authentication approval method:
- Approve or deny: The customer receives a push notification and confirms the sign-in by selecting Approve or Deny in the mobile app.
- Approve with number matching: The customer receives a push notification and verifies the sign-in by selecting the number displayed during authentication. This provides additional protection against accidental or fraudulent approval requests.
Number matching and the FIDO authenticator requirement both add friction, but they protect your customers against MFA fatigue attacks, where an attacker floods a customer with approval requests hoping one gets accepted. Weigh the security benefit against the added friction for your use case.
Challenge behavior
- Every challenge is unique. Resending a push notification creates a new challenge and invalidates the previous one.
- If a customer has multiple devices enrolled, answering the challenge on one device removes the request from the others.
- If the challenge expires or the device is unreachable, the customer can resend the notification or fall back to another enrolled MFA method.
Related pages
- Push notification MFA in the login journey
- Push notification MFA enrollment in the registration journey
- How customers manage adaptive access
Updated about 3 hours ago
Did this page help you?

