Push notification MFA
The push notification multi-factor authentication (MFA) method provides an additional layer of security during the Authenticate step by sending an approval request to the customer's enrolled mobile device. Instead of typing a passcode, the customer answers the challenge in your brand's mobile app.
What customers experience
- If the customer has more than one MFA method enrolled, the MFA selection screen shows their enrolled device as an option (for example, Push notification to Natalie's iPhone).
- Strivacity sends a push notification to the device, and the browser displays a Check your mobile device screen while it waits for the answer.
- The customer answers the challenge in the mobile app. Depending on the approval method set in the Adaptive Access policy, they either:
- select Approve or deny, or
- select the number shown on the screen where they're logging in (number matching).
- Once approved, the browser automatically continues the login, and the customer returns to their original device to access their account.
The challenge shows the customer when and from where the sign-in was triggered, so they can spot a request they didn't start. If the request wasn't theirs, they deny it, and the sign-in fails.
Features
- Resending notifications: If the customer doesn't receive the notification, they can resend it. Sending a new push notification creates a new challenge and invalidates the previous one.
- Multiple enrolled devices: The challenge goes to the customer's enrolled devices, and answering on one device removes the request from the others.
- Fallback to other MFA methods: If the customer's device is offline or they prefer a different method, they can select Choose a different authentication method to switch to another option available to them.
- Challenge expiry: Challenges expire after the approval lifetime set in the Adaptive Access policy (60 seconds by default). An expired or failed challenge shows the customer a retry screen with the option to try again or choose a different method.
Settings that affect this step
- Adaptive Access policy: Controls whether push notification MFA is enabled, the approval method (Approve or Deny, or number matching), the challenge lifetime, and whether a registered FIDO authenticator is required to open the notification.
- Push notification configuration: The instance-level delivery service configuration that connects Strivacity to your app's Firebase or APNs credentials.
- Branding policy: Controls the appearance and text of the challenge screens.
Event logging
Push notification MFA activity is captured as MFA Push (/mfaPush) account events, so you can track challenges and their outcomes in Account events.
Updated about 3 hours ago
Did this page help you?

