Introduction
This article guides clients through the necessary steps to prepare for enabling Client-Side Multi-Factor Authentication (MFA) within Reward Gateway | Edenred (RGER). This feature allows RGER to recognize and trust the Multi-factor Authentication that your organization performs through your Identity Provider (IdP), such as Okta, Microsoft Azure, or Edenred Connect, minimizing additional MFA prompts when accessing RGER applications.
Outcomes
By following this guide, you will be able to:
- Ensure your IdP is properly configured for MFA and Single Sign-On (SSO)
- Work with your Reward Gateway | Edenred contact to enable Client-side MFA
- Verify successful integration and a seamless sign-in experience on web and mobile platforms
Prerequisites
Before configuring Client-Side MFA, please ensure:
- Your organization uses Okta, Microsoft Azure, or Edenred Connect as your IdP
- MFA enforcement is enabled and active on your company's IdP.
- Single Sign-On (SSO) is configured on your platform and working successfully.
- You have liaised with your CSM or Reward Gateway | Edenred contact who will coordinate the configuration process.
Step-by-step Configuration Process
Step 1. Confirm your MFA IdP setup
Ensure your IdP (Okta, Microsoft Azure, or Edenred Connect) has MFA enabled for users accessing your benefits platform.
Step 2. Configure IdP
Configure your IdP to send the correct authentication context class reference (ACR) or authentication level claims in the SAML or OIDC tokens to Reward Gateway IdP.
Ensure your IdP has MFA enabled for users accessing Reward Gateway services. This signal informs Reward Gateway that the user has successfully completed MFA.
For Okta:
To achieve this, client Okta administrators need to configure their custom SAML application in Okta to pass Dynamic Authentication Context.
1. Navigate to the App Integration
> Open the Okta Admin Console
> Go to Applications > Applications and select the SAML 2.0 app integration they created for your platform
> Click on the General tab and find the SAML Settings section, then click Edit
2. Configure the Custom SAML Attribute Statement
> Click Next to proceed to the Configure SAML step
> Scroll down to the Attribute Statements (optional) section
> Add a new row with the following values:
- Name: amr
- Name format: Unspecified
- Value: session.amr
See also; Pass Dynamic Authentication Context
For Microsoft Azure:
Client administrators should follow these steps:
> Go to Microsoft Entra admin center and sign in as at least a Cloud Application Administrator
> Navigate to Entra ID > Enterprise applications > [Your App e.g RG Engagement] > Single sign-on > User Attributes & Claims
> Click Edit under User Attributes & Claims:
> Click Add new claim
> Alternatively, select Token configuration under the app registration to add Optional claims (like MFA)
Clients can follow this guide; Configure optional claims - Microsoft identity platform, or read more here; Customize SAML token claims - Microsoft identity platform
For Edenred Connect
Your Edenred Connect administrator will set up the IdP to ensure claims are sent to Reward Gateway.
Step 3. Confirm claims in the token
> Confirm that the claims in the token include MFA evidence. Example claims we expect to see:
Standard Context
<AuthnContextClassRef>
urn:oasis:names:tc:SAML:2.0:ac:classes:MobileTwoFactorContract
urn:oasis:names:tc:SAML:2.0:ac:classes:TelephonyNominalTwoFactor
urn:oasis:names:tc:SAML:2.0:ac:classes:TimeSyncToken
http://schemas.microsoft.com/claims/multipleauthn (Azure)
http://schemas.microsoft.com/ws/2008/06/identity/authenticationmethod/x509 (Azure)
</AuthnContextClassRef>
Custom Attributes
Azure and Okta, expected amr values: email_otp, phone_number_otp, trusted_device, device_challenge, mfa, otp, totp, fido.
Edenred Connect expected amr values: password, external, email_otp, trusted_device.
Step 4. Verify SSO is functioning correctly
Test normal SSO works through your IdP without errors.
Step 5. Discuss Client-Side MFA enablement with your Reward Gateway | Edenred contact
Request that the feature be enabled. Your contact with confirm when this has been set up.
Step 6. After confirmation of enablement, conduct testing
Log in via your IdP with Client-side MFA enabled.
Confirm members are not prompted for a second MFA challenge when logging into the platform.
Perform the same test on mobile devices for the Engage app
Step 7. Report any issues with MFA
If you experience unexpected MFA prompts or login difficulties, share any details with your CSM (or other Reward Gateway | Edenred contact) for troubleshooting.
Troubleshooting Tips
- If you still see multiple MFA prompts, ensure your IdP is passing the correct authentication context to Reward Gateway IdP.
- Your eward Gateway | Edenred contact may review internal logs to confirm whether MFA signals are correctly received.
- Confirm that mobile the appropriate SSO is enabled, if mobile experience is inconsistent.
Best Practices
- Maintain active communication with your Reward Gateway | Edenred contact throughout setup.
- Validate your existing SSO and MFA setup independently before enabling Client-Side MFA.
- Test thoroughly on all platforms your employees use (web and mobile).
- Contact support promptly if issues arise - this facilitates log review and quicker resolution.
Comments
0 comments
Please sign in to leave a comment.