Introduction
This article provides an overview of the Client-side MFA (Multi-factor Authentication) feature. It is written for a client audience.
About Client-Side MFA
Client-side Multi-Factor Authentication (MFA) is a security feature that allows Reward Gateway Identity Provider (RG IdP) to recognize and trust the MFA your organization already performs through your own Identity Provider (IdP), such as Okta, Microsoft Azure, or Edenred Connect.
Traditionally, when members log in to your platform, they may be asked to complete MFA twice: once via your company’s IdP and again within RG IdP. This feature prevents the second MFA challenge from the Reward Gateway IdP after having already authenticated with your own company's MFA IdP. It removes this second MFA step by trusting the initial MFA, which improves your sign-in experience without compromising security.
Who Benefits From This Feature
Clients who have Single Sign-on enabled, and who have MFA enabled for members authenicating into RG platform.
How It Works
- Members log into your platform as normal.
- Your company's Identity Provider authenticates and verifies your company's MFA — for example, via an authenticator app, text message, or biometric.
- When logging into RG via SSO, the RG IdP receives confirmation that MFA was successfully completed by your company's IdP.
- RG IdP then bypasses its own MFA prompt, allowing you to access the platform smoothly.
- If RG IdP cannot confirm MFA from your own IdP, the member will be prompted to complete MFA within the platform as a fallback.
Prerequisites
To benefit from Client-side MFA, the following must be in place:
- Your organisation must be using Okta, Microsoft Azure, or Edenred Connect as your Identity Provider.
- Multi-factor Authentication (MFA) must be enabled and enforced on your Identity Provider side.
- Single Sign-On (SSO) must be configured and functioning correctly between your Identity Provider and RG IdP.
- Client-side MFA must enabled for your programme (see: How To Enable Client-side MFA).
- If you access your platform via mobile devices (i.e. via the Engage app), mobile SSO must also be enabled to provide a consistent MFA bypass experience.
RG IdP receives the required MFA authentication context via your Identity Provider’s authentication response (e.g., specific attribute claims).
Benefits for You and Your Organisation
- Simplified Login: Fewer MFA prompts mean faster and smoother access.
- Improved User Experience: Reduces frustration caused by repeated verification steps.
- Consistent Security: Trusts your existing strong MFA without sacrificing security.
- Supports Mobile Access: Works on both web and mobile platforms when configured.
- Reduced Support Requests: Minimizes login-related help desk issues.
Security and Privacy
Client-side MFA does not weaken security. RG IdP carefully verifies authentication signals from your company's Identity Provider. If signals are absent, invalid, or suspicious, RG IdP will require its own MFA to maintain protection.
All authentication decisions are logged securely to support monitoring and audit requirements.
Help and Support
For assistance or questions about Client-side MFA, contact your Client Success Manager or Client Support team.
Comments
0 comments
Please sign in to leave a comment.