Device authenticator
During a login journey, customers can enroll a mobile device as an authenticator or use an already enrolled device to complete MFA, depending on the journey and Adaptive Access configuration.
Device enrollment optionsCustomers can enroll a device:
- During registration, as part of MFA enrollment.
- During a login journey, when device enrollment is configured.
- From My Account under Security settings > Multi-factor authentication (MFA).
What customers experience
- If multiple MFA methods are available, the customer selects push notification authentication.
- If the customer has more than one enrolled device, Strivacity displays the available devices and the customer selects which device should receive the authentication request.
- Strivacity sends the push notification to the selected device. The browser displays Check your device while it waits for a response.
- The customer responds in the mobile application. Depending on the authentication method configured for the push notification, they either:
- Approve or deny the request, or
- Select the number shown in the authentication journey.
- After the customer approves the request, the login continues automatically.
The mobile application can display context about the authentication request, such as the browser, location, and time, to help the customer identify requests they did not initiate.
Features
- Resending notifications: If the customer does not receive the push notification, they can select Resend notification. Strivacity creates a new challenge and invalidates the previous one.
- Multiple enrolled devices: If several devices are enrolled, the customer selects the device that should receive the push notification.
- Challenge expiry or failure: If the challenge expires or fails, Strivacity displays a generic Access denied screen without indicating the reason. The customer can select Back to login to start the login process again.
- Returning to login: Customers cannot switch directly to another MFA method while Strivacity is waiting for the push response. Selecting Back to login restarts the login process.
Settings that affect this step
- Adaptive Access policy: Controls whether Push MFA is available, whether enrollment is optional or mandatory, and the push notification approval lifetime.
- Push notification configuration: Controls the mobile application, authentication method, deep-link URL, and platform-specific delivery service configuration.
- Branding policy: Controls the appearance of the Push MFA screens displayed in the web journey. The appearance of screens within the mobile application is controlled by the application itself.
Event logging
Push notification MFA activity is captured as MFA Push (/mfaPush) account events, so you can track challenges and their outcomes in Account events.
Updated about 2 hours ago
Did this page help you?

