In EmpowerID multi-factor authentication (MFA) is a flexible, points based system that allows you to specify the number and types of factors that users must present when authenticating, as well as the weight or point value associated with each of those factors. When users reach the designated point threshold, they are authenticated and granted access to the system. In order to ease user adoption, EmpowerID supports a number of MFA types out of the box. These include:

If an MFA Type is added to an application, users must authenticate themselves through the MFA Type before EmpowerID grants access to the application.

Assign MFA Types

  1. On the navbar, expand Single Sign-On and click Applications.

  2. From the Applications tab of the Find Applications page, search for the application to which you want to apply LoA points and click the Display Name link for that policy.


  3. On the Application Details page that appears, select the SSO tab in the lower pane and expand the Multifactor Authentication accordion.

  4. Click the Add Type (+) button to the right of the grid.

  5. In the dialog that appears, click the Type drop-down and select one of the above-mentioned MFA Types.

  6. Set the priority for the type in the Priority field. The lower the number the higher the priority. When more than one MFA Type is assigned to an application, EmpowerID directs users to the MFA Type with the highest priority first and then to the MFA Type with the next highest priority and so on until the point threshold for the application is met.

  7. Specify whether the MFA type is required. If required, users accessing the application must authenticate using the type. When an application has more than one MFA Type that is required, users must authenticate using each type in the order specified by the priority for the type.

  8. Click Save.