Introduction
This article guides clients through the necessary steps to prepare for enabling Client-Side Multi-Factor Authentication (MFA) within Reward Gateway | Edenred (RGER). This feature allows RGER to recognize and trust the Multi-factor Authentication that your organization performs through your Identity Provider (IdP), such as Microsoft Azure, minimizing additional MFA prompts when accessing RGER applications.
Note: This guide is designed to be only used for Microsoft Azure.
Outcomes
By following this guide, you will be able to:
- Ensure your IdP is properly configured for MFA and Single Sign-On (SSO)
- Work with your Reward Gateway | Edenred contact to enable Client-side MFA
- Verify successful integration and a seamless sign-in experience on web and mobile platforms
Prerequisites
Before configuring Client-Side MFA, please ensure:
- Your organization uses Microsoft Azure as your IdP.
- MFA enforcement is enabled and active on your company's IdP.
- Single Sign-On (SSO) is configured on your platform and working successfully.
- You have liaised with your CSM or Reward Gateway | Edenred contact who will coordinate the configuration process.
Step-by-step Configuration Process
Step 1. Confirm your MFA IdP setup
- Ensure your IdP (Microsoft Azure) has MFA enabled for users accessing your benefits platform.
Step 2. Configure IdP
- Configure your IdP to send the correct authentication context class reference (ACR) or authentication level claims in the SAML or OIDC tokens to Reward Gateway IdP.
- Ensure your IdP has MFA enabled for users accessing Reward Gateway services. This signal informs Reward Gateway that the user has successfully completed MFA.
Step 3. Platform-Specific Instructions
How to Check if SSO is Enabled:
- In Microsoft Entra Admin Center, go to Enterprise Applications > your app.
- Under Single Sign-On, confirm SAML configuration is correct.
How to Check if MFA is Enabled:
- In Entra ID > Security > Conditional Access, ensure there are policies requiring MFA for users/apps.
- In Entra ID > Users > Multi-Factor Authentication, confirm user MFA status (Enabled/Enforced).
- Check the user profile for registered authentication methods.
How to Test Your SAML Response:
Test the SAML response to confirm it reflects a successful MFA authentication:
- Perform a sign-in as a test user.
- Capture the SAML response (see AWS guide or use browser tools/SAML tracing extensions).
- Inspect the response for MFA claims as described below.
- Look for an
<AuthenticationStatement>or<AuthnContextClassRef>indicating MFA:
<saml:AuthenticationStatement AuthenticationMethod="http://schemas.microsoft.com/claims/multipleauthn"><saml:Subject> ... </saml:Subject></saml:AuthenticationStatement><saml:AuthenticationStatement AuthenticationMethod="http://schemas.microsoft.com/ws/2008/06/identity/authenticationmethod/x509">
<saml:Subject> ... </saml:Subject>
</saml:AuthenticationStatement>
Step 4. Verify SSO is functioning correctly
Test normal SSO works through your IdP without errors.
Step 5. Discuss Client-Side MFA enablement with your Reward Gateway | Edenred contact
Request that the feature be enabled. Your contact with confirm when this has been set up.
Step 6. After confirmation of enablement, conduct testing
- Log in via your IdP with Client-side MFA enabled.
- Confirm members are not prompted for a second MFA challenge when logging into the platform.
- Perform the same test on mobile devices for the Engage app
Step 7. Report any issues with MFA
If you experience unexpected MFA prompts or login difficulties, share any details with your CSM (or other Reward Gateway | Edenred contact) for troubleshooting.
Comments
0 comments
Please sign in to leave a comment.