MFA Authentication for multiple Tenants is Tedious

so I have a weird question…

Now that we are signing in using MFA instead of security questions, I noticed that we get this screen after typing in our user name and password:
image

To get the Authentication Code you need to do the following:

  1. Find your phone
  2. Log into the authentication app on your phone
  3. Scroll through the 100s of Codes for other apps until you get to the Sailpoint one
  4. Make sure it’s for the correct Sailpoint instance
  5. Type the code in
  6. You’re in!

This is a simple process and great security, but when I log into other apps like Google, Microsoft, I noticed they have less friction for their MFA process.

Stick with me here.

To log into Delinea, which goes through Microsoft MFA, I don’t even have to type a password. SSO automatically logs me in, but let’s just say I had to. Just like with above, after typing in my username and password I get the following screen:

Instead of having to get an Authentication Code, I need to just approve the sign in request. Steps:

  1. Find your phone.
  2. The request is already on the screen, so just type in the number shown
  3. You’re logged in

There’s far less friction to getting logged in, especially considering how fast these logins expire after inactivity.

My question:

Is it possible to implement something like that with Sailpoint IDN? :slight_smile:

I was just having a similar discussion today with another developer. This is compounded when you are testing, and the users you are testing with need to have MFA set up on their phones too.

I would be interested to hear recommendations for how to handle this with other developers, or from SailPoint on whether this is coming in a future update, or they have a suggested alternate process for this.

1 Like

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.