Skip to main content

MFA methods

XFA adds multi-factor authentication (MFA) to an integration with three methods: Silent MFA, TOTP and passkeys. You can enable one or more of them per integration. This page compares the methods and explains which one users get when several are enabled.

Compare the methods

Silent MFATOTPPasskey
What the user doesNothing on a trusted device. A new device is approved in the XFA App or by emailEnters a 6-digit code from an authenticator appConfirms with a fingerprint, face, screen lock or security key
What it provesThe user is on a device they trusted with XFAThe user has their authenticator appThe user holds the passkey and unlocked it with a fingerprint, face, screen lock or PIN
Needs the XFA AppYesNoNo
Tied to one deviceYes, each device is trusted separatelyNoNo, unless the passkey is kept on a single device or security key

For setup and user experience per method, see Silent MFA, TOTP and Passkeys.

Enable a method

  1. Go to the XFA Dashboard and navigate to Enforcement
  2. Click Manage on the integration you want to configure
  3. Under Multi-Factor Authentication, switch on the methods you want:
    • Enable XFA Multi-Factor Authentication for Silent MFA
    • Enable TOTP (Time-based One-Time Password) for TOTP
    • Enable passkeys for passkeys

MFA is available on every integration type except OAuth2. When you switch off the last enabled method, XFA asks you to confirm, because the integration then has no MFA.

Which method users get

When an integration has one method enabled, users go straight to it.

When it has more than one:

  • A user who already chose a method in this browser goes straight to it.
  • Otherwise, a user who has already set up a method is sent to it. Silent MFA comes first, then TOTP, then passkeys.
  • A user who has not set up any method sees Choose verification method and picks one. The browser remembers that choice for next time.

On the verification screen, users can switch to another method with Set one up, next to Want to use a different method?. In the XFA mobile app, this is Use a different method.

Reset a user's MFA

  • Reset MFA authentication removes all of a user's MFA: trusted devices, TOTP and passkeys. Go to Devices, open the People tab and choose it from the actions menu next to the user. The user sets up MFA again on their next sign-in.
  • Reset 2FA removes Silent MFA for one device only. Choose it from the actions menu next to the device on the Devices tab. TOTP and passkeys are not tied to a device and stay in place.