Prompt
How do I add MFA with enterprise SSO?
Latest observation
Oct 7, 2026
OpenAI APIWeb search: off
Adding MFA with enterprise SSO usually means the SSO provider handles the MFA challenge, and your app trusts the SSO assertion after the user authenticates.
Typical setup
-
Choose an identity provider (IdP)
Examples: Okta, Azure AD / Entra ID, Google Workspace, OneLogin, Auth0, Ping. -
Configure SSO for your app
- Use SAML 2.0 or OIDC / OpenID Connect
- Register your app in the IdP
- Configure redirect URLs / ACS URL / entity ID / client secret or signing cert
-
Enable MFA in the IdP
- Turn on MFA policies for users, groups, apps, or conditional access
- Common MFA methods:
- Authenticator app / TOTP
- Push approval
- SMS (less recommended)
- FIDO2 / WebAuthn security keys
- Biometrics via device auth
-
Make your app rely on the IdP authentication result
- Do not implement your own MFA if the IdP is authoritative
- Check claims/assertions like:
- authenticated user identity
- email / groups / roles
- authentication context, if needed
- For OIDC, look at ID token claims; for SAML, inspect the assertion
-
Optionally enforce step-up auth
- If certain actions are sensitive, require “strong auth” again
- With OIDC, request higher assurance using
acr_valuesor similar - With SAML, use AuthnContext if supported by your IdP
What this looks like in practice
- User clicks “Sign in with Company SSO”
- IdP redirects them to MFA if required
- User completes MFA at the IdP
- IdP sends your app a SAML assertion or OIDC token
- Your app creates a session
Best practices
- Prefer phishing-resistant MFA: WebAuthn/FIDO2 over SMS
- Use conditional access if your IdP supports it
- Don’t store or manage MFA secrets in your app unless you’re doing local auth
- Validate tokens/assertions carefully:
- signature
- issuer
- audience
- expiration
- nonce/state for OIDC
- Support break-glass/admin recovery flows
If you want MFA inside your app too
That’s a different model:
- SSO for primary login
- App-level MFA for sensitive actions
- Useful if you need extra assurance beyond the IdP
If you tell me which SSO provider you use and whether you want SAML or OIDC, I can give you exact setup steps.