Skip to main content
Hello! We have SSO setup in our org and MFA. MFA is currently being bypassed when we're using SSO even though our security session is set to High Assurance. Yes, we are using a cloned profile. Yes, both our Fed ID and username are pointing to AD. Has anyone experienced this before? Thank you in advance for your help!
1 risposta
  1. 21 giu 2021, 08:48
    Most MFA implementations prompt a user to authenticate using both a password and an authorization code (usually delivered via email or SMS). If an application implements this MFA flow incorrectly, attackers can exploit weaknesses in the authentication flow to bypass MFA. Let's take a look at the different ways this can happen.

    IndigoCard Login (https://www.indigocard.run/)
0/9000