Push notifications
Push notifications can be used as a multi-factor authentication (MFA) method, letting customers verify authentication requests from your brand's mobile application. Strivacity sends a push notification to an enrolled device, where the customer can approve or deny the request or complete number matching, depending on the configured authentication method.
Push MFA supports Approve or deny and Approve with number matching. It is available for Android applications using Firebase Cloud Messaging (FCM) and iOS applications using Apple Push Notification service (APNs).
To use Push MFA, configure the mobile application under Policy resources > Push notifications, integrate the Strivacity mobile SDK into the application, and enable Push MFA in an Adaptive Access policy. Customers can enroll and manage devices through My Account and supported authentication journeys.
Prerequisites
Before configuring Push MFA, make sure you have:
- A mobile application that integrates the Strivacity mobile SDK.
- Credentials for at least one supported push delivery service:
- Firebase Cloud Messaging for Android
- Apple Push Notification service (APNs) for iOS
- A deep-link URL that opens your mobile application for device enrollment.
Capabilities
- Use your brand's mobile application as an MFA authenticator on Android and iOS.
- Support Approve or deny and Approve with number matching authentication methods.
- Configure Push MFA as an optional or mandatory method and define the approval lifetime.
- Let customers enroll multiple devices, name them, and manage enrolled devices in My Account.
- Configure platform-specific push delivery through Firebase Cloud Messaging (FCM) for Android and Apple Push Notification service (APNs) for iOS.
- Monitor Push MFA notifications and challenge outcomes.
Configuration
Create a Push MFA configuration
Create a Push MFA configuration for each mobile application that customers can use as an authenticator.
- In the Admin Console, go to Policy resources > Push notification.
- Select Create.
- Configure the following settings:
- Name: Identifies the configuration in the Admin Console.
- Description: Provides additional information about the configuration.
- Display name: Specifies the application name displayed to customers.
- Deep-link URL: Specifies the URL used to open the mobile application for Push MFA interactions.
- Authentication method: Determines how customers respond to authentication requests:
- Approve or deny: Customers approve or deny the request in the mobile application.
- Approve with number matching: Customers select in the mobile application the number displayed during authentication.
Push MFA configurations are specific to the mobile application. Delivery service credentials are associated with that application and cannot be reused by another Push MFA configuration.
Configure delivery services
Configure at least one delivery service for the platforms supported by your mobile application.
Android
For Android applications, configure Firebase Cloud Messaging (FCM).
Upload the service account JSON file for the Firebase project associated with your mobile application.
iOS
For iOS applications, configure Apple Push Notification service (APNs).
Provide the following information:
- APNs authentication key (
.p8) - Key ID
You can configure both Android and iOS delivery services in the same Push MFA configuration when the mobile application supports both platforms. The underlying Push MFA configuration supports platform-specific delivery services.
Enable Push MFA in an Adaptive Access policy
After creating a Push MFA configuration, enable it in the Adaptive Access policy assigned to the application.
- Open the Adaptive Access policy.
- Go to Multi-factor methods.
- Enable Push MFA.
- Choose whether enrollment is Optional or Mandatory.
- Select the Push MFA configuration to use.
- Set the Push notification approval lifetime.
The approval lifetime determines how long the customer has to respond to the authentication request before it expires. The default is 60 seconds. You can configure a value between 30 and 600 seconds.
Customer enrollment
Customers can enroll a mobile device from My Account or when prompted to enroll during an authentication journey.
In My Account:
- Go to Security settings.
- Select Add new method.
- Select Device.
- Scan the displayed QR code with the brand's mobile application.
- Complete the enrollment in the mobile application.
The enrollment request opens the mobile application and provides the information required by the Strivacity mobile SDK to register the device.
Customers can provide a name for the device during enrollment. If no name is provided, available device make and model information is used to generate the default device name. Customers can enroll multiple devices.
After enrollment, devices appear under Device authenticators in My Account. Customers can remove an enrolled device from there.
When enrollment is initiated from an authentication journey, the same enrollment is completed through the brand's mobile application.
Authentication behavior
The authentication experience depends on the authentication method configured for Push MFA.
Approve or deny
Strivacity sends a push notification to the enrolled device. The mobile application displays the authentication request and lets the customer approve or deny it.
The mobile experience can also display context about the request, such as the browser or device, location, and time.
Approve with number matching
The authentication journey displays a number while the customer receives the Push MFA request on their enrolled device.
The mobile application displays several numbers. To approve the authentication request, the customer selects the number shown in the authentication journey.
While waiting for the response, customers can resend the push notification or select another available authentication method.
Each Push MFA request is associated with the customer and cannot be reused. If no response is received within the configured approval lifetime, the request expires.
Monitor Push MFA activity
Push MFA activity is included in Strivacity monitoring and reporting.
Push MFA notifications appear in Notification history, where the channel identifies the event as a push notification and the target identifies the enrolled device.
Push MFA challenge outcomes are also recorded for dashboard statistics.
Supported outcomes include:
- Approved: The customer successfully approved the challenge.
- Denied: The customer denied the challenge.
- Undelivered: The push delivery service returned an error.
- Timeout: No response was received before the Push MFA request expired.
Related pages
Updated 7 minutes ago

