PingOne

Configuring MFA settings

You can define MFA settings for end users, such as the maximum number of methods that a user can set up for authentication, authentication method selection, and account lockout settings. These settings are applied at the environment level.

Steps

  1. Go to Authentication > MFA Settings.

  2. For Default MFA status for new users, specify whether MFA should be enabled by default for a user when their account is created.

    Default MFA status for new users is set to Enabled by default for all environments created after August 20, 2024.

  3. For Maximum allowed methods, select the maximum number of authentication methods that users can set up for their accounts. The default is 5.

    Users can have multiple authentication methods using the same device. For example, an end user could have SMS, voice, biometrics, and an authenticator app all on a single mobile device.

    If you reduce the maximum value, existing methods are not affected. For example, if a user has 4 authentication methods set up, but you reduce the maximum number to 3, the user will not have to remove an existing authentication method.

  4. If some of your users will be pairing devices that have phone numbers with extensions, set the Phone numbers with extensions option to Enabled.

  5. For Account lockout, enter or edit the following:

    • Account lockout: The maximum number of incorrect MFA authorization actions a user can attempt (such as entering an incorrect OTP or declining a push confirmation on a mobile device) before the account is locked.

      This value includes MFA authentication attempts across all configured devices.

    • Account lockout duration: The amount of time (in seconds) to keep the account locked after the failure count is exceeded. The account will automatically unlock after the specified time passes.

  6. Select the type of key to use for pairing of devices.

    Choose from:

    • 12-digit numeric

    • 16-character alphanumeric

  7. Click Save.

Next steps

You can unlock or disable a user account on the user details page. Learn more in Enabling or unlocking a user account or device.