Introduction
This article provides an overview of the Client-side MFA (Multi-factor Authentication) feature. It is written for a client audience.
About Client-Side MFA
Client-Side Multi-Factor Authentication (MFA) is a security feature that allows Reward Gateway to recognize and trust the MFA your organization already performs through your Identity Provider (IdP), such as Okta, Microsoft Azure, or Edenred Connect.
Traditionally, when you log in to Reward Gateway, you may be asked to complete MFA twice: once via your company’s IdP and again within Reward Gateway. Client-Side MFA removes this duplicate step by trusting the initial MFA, improving your sign-in experience without compromising security.
How Does It Work?
- You start logging into Reward Gateway using your organization’s Single Sign-On (SSO) system.
- Your Identity Provider authenticates you and verifies your MFA — for example, via an authenticator app, text message, or biometric.
- Reward Gateway receives confirmation that MFA was successfully completed by your IdP.
- Reward Gateway then bypasses its own MFA prompt, allowing you to access the service smoothly.
- If Reward Gateway cannot confirm MFA from your IdP, you will be prompted to complete MFA within Reward Gateway as a fallback.
Prerequisites
To benefit from Client-Side MFA, the following must be in place:
- Your organisation uses Okta, Microsoft Azure, or Edenred Connect as your Identity Provider.
- Multi-factor Authentication (MFA) is enabled and enforced on your Identity Provider side.
- Single Sign-On (SSO) is configured and functioning correctly between your Identity Provider and Reward Gateway.
- Reward Gateway features Client-Side MFA enabled for your Business Unit or Programe.
- If you access Reward Gateway via mobile devices (Engage app), mobile SSO should also be enabled to provide a consistent MFA bypass experience.
- Reward Gateway receives the required MFA authentication context via your Identity Provider’s authentication response (e.g., specific attribute claims).
Benefits for You and Your Organisation
- Simplified Login: Fewer MFA prompts mean faster and smoother access.
- Improved User Experience: Reduces frustration caused by repeated verification steps.
- Consistent Security: Trusts your existing strong MFA without sacrificing security.
- Supports Mobile Access: Works on both web and mobile platforms when configured.
- Reduced Support Requests: Minimizes login-related help desk issues.
Security and Privacy
Client-Side MFA does not weaken security. Reward Gateway carefully verifies authentication signals from your Identity Provider. If signals are absent, invalid, or suspicious, Reward Gateway will require internal MFA to maintain protection.
All authentication decisions are logged securely to support monitoring and audit requirements.
Help and Support
For assistance or questions about Client-Side MFA, contact your internal Reward Gateway representative or support team. Additional guides and support materials are available upon request.
Comments
0 comments
Please sign in to leave a comment.