MFA methods
XFA adds multi-factor authentication (MFA) to an integration with three methods: Silent MFA, TOTP and passkeys. You can enable one or more of them per integration. This page compares the methods and explains which one users get when several are enabled.
Compare the methods
| Silent MFA | TOTP | Passkey | |
|---|---|---|---|
| What the user does | Nothing on a trusted device. A new device is approved in the XFA App or by email | Enters a 6-digit code from an authenticator app | Confirms with a fingerprint, face, screen lock or security key |
| What it proves | The user is on a device they trusted with XFA | The user has their authenticator app | The user holds the passkey and unlocked it with a fingerprint, face, screen lock or PIN |
| Needs the XFA App | Yes | No | No |
| Tied to one device | Yes, each device is trusted separately | No | No, unless the passkey is kept on a single device or security key |
For setup and user experience per method, see Silent MFA, TOTP and Passkeys.
Enable a method
- Go to the XFA Dashboard and navigate to Enforcement
- Click Manage on the integration you want to configure
- Under Multi-Factor Authentication, switch on the methods you want:
- Enable XFA Multi-Factor Authentication for Silent MFA
- Enable TOTP (Time-based One-Time Password) for TOTP
- Enable passkeys for passkeys
MFA is available on every integration type except OAuth2. When you switch off the last enabled method, XFA asks you to confirm, because the integration then has no MFA.
Which method users get
When an integration has one method enabled, users go straight to it.
When it has more than one:
- A user who already chose a method in this browser goes straight to it.
- Otherwise, a user who has already set up a method is sent to it. Silent MFA comes first, then TOTP, then passkeys.
- A user who has not set up any method sees Choose verification method and picks one. The browser remembers that choice for next time.
On the verification screen, users can switch to another method with Set one up, next to Want to use a different method?. In the XFA mobile app, this is Use a different method.
Reset a user's MFA
- Reset MFA authentication removes all of a user's MFA: trusted devices, TOTP and passkeys. Go to Devices, open the People tab and choose it from the actions menu next to the user. The user sets up MFA again on their next sign-in.
- Reset 2FA removes Silent MFA for one device only. Choose it from the actions menu next to the device on the Devices tab. TOTP and passkeys are not tied to a device and stay in place.
Related
- Silent MFA
- TOTP
- Passkeys
- Verification methods, the user guide