Introduction
This article guides clients through the necessary steps to prepare and enable Client-Side Multi-Factor Authentication (MFA) within Reward Gateway | Edenred (RGER). This feature allows RGER to recognize and trust the Multi-factor Authentication that your organization performs through your Identity Provider (IdP), such as Okta, Microsoft Azure, or Edenred Connect, minimizing additional MFA prompts when accessing RGER applications.
Outcomes
By following this guide, you will be able to:
- Ensure your Identity Provider (IdP) is properly configured for MFA and Single Sign-On (SSO)
- Work with your Reward Gateway contact and internal teams to enable Client-Side MFA
- Verify successful integration and a seamless sign-in experience on web and mobile platforms
Prerequisites
Before configuring Client-Side MFA, please ensure:
- Your organization uses Okta, Microsoft Azure, or Edenred Connect as your Identity Provider.
- MFA enforcement is enabled and active on your external IdP.
- Single Sign-On (SSO) is already configured with Reward Gateway and is working successfully.
- You have liaised with your Reward Gateway representative or Business Unit contact who will coordinate the configuration process internally.
Step-by-step Configuration Process
- Confirm your Identity Provider setup
Ensure your IdP (Okta, Microsoft Azure, or Edenred Connect) has MFA enabled for users accessing Reward Gateway services. - Verify SSO is functioning correctly
Test normal sign-in works through your IdP without errors. - Discuss Client-Side MFA enablement with your Reward Gateway contact
Request that the feature be enabled at your Business Unit or Scheme level. - Reward Gateway will submit an internal request
Your Business Unit or SEM will raise a support ticket with our Identity team to enable Client-Side MFA feature flags. - After confirmation of enablement, conduct testing
- Log in via your IdP with MFA enabled.
- Confirm you are not prompted for a second MFA challenge within Reward Gateway.
- Perform the same test on mobile devices.
- Report any issues to your Reward Gateway contact
If you experience unexpected MFA prompts or login difficulties, share details for further troubleshooting.
Troubleshooting Tips
- If you still see multiple MFA prompts, ensure your IdP is passing the correct authentication context to Reward Gateway.
- Your Reward Gateway support team may review internal logs to confirm whether MFA signals are correctly received.
- Confirm that mobile users have the appropriate SSO feature flag enabled if mobile experience is inconsistent.
Best Practices
- Maintain active communication with your Reward Gateway Business Unit contacts throughout setup.
- Validate your existing SSO and MFA setup independently before enabling Client-Side MFA.
- Test thoroughly on all platforms your employees use (web and mobile).
- Engage Reward Gateway support promptly if issues arise - this facilitates log review and quicker resolution.
Comments
0 comments
Please sign in to leave a comment.