Announcing the Saviynt Knowledge Exchange unifying the Saviynt forums, documentation, training,
and more in a single search tool across platforms. Read the announcement here.

MFA for Admin Users

sandeepgudipudi
New Contributor III
New Contributor III

Requirement:

We are using Azure as SSO for End Users and We want to enable MFA for Admin Accounts/locally created users which are not SSO Accounts.

I referred below documents and implemented steps but nothing is working neither prompting for MFA

Using Okta as provider in Settings>MFA - Security Considerations (saviyntcloud.com)

Using REST Connector for Okta- Configuring Step-up Authentication and Verification (saviyntcloud.com)

12 REPLIES 12

Saathvik
All-Star
All-Star

@sandeepgudipudi : No you cannot enable MFA for locally created account unless same account exists in Identity provider. Can you please explain the use case why you want to enable MFA for accounts created locally? If use case is just to avoid login through non-sso URL then Saviynt in general blocks the non-sso URL from being accessed unless you put in a exception.


Regards,
Saathvik
If this reply answered your question, please Accept As Solution and give Kudos to help others facing similar issue.

sandeepgudipudi
New Contributor III
New Contributor III

Hi,

we figured out a way to local login even SSO is enabled. How ever i disabled SSO and tried the above steps still MFA is not prompted

Does MFA not working for any user or admin users?


Regards,
Rushikesh Vartak
If you find the response useful, kindly consider selecting Accept As Solution and clicking on the kudos button.

MFA is not working for all users, its not even prompting for MFA

  • Any error in Saviynt logs ?
  • Any OKTA Login related audit logs?

Regards,
Rushikesh Vartak
If you find the response useful, kindly consider selecting Accept As Solution and clicking on the kudos button.

sandeepgudipudi
New Contributor III
New Contributor III

There are no logs specific to MFA

I configured for "Saviynt to generate OTP" as described in the document for email OTP. Post Login with username/password the saviynt is not prompting for MFA.
 
 
Section: Configuring OTP Authentication Methods

Please share config screenshot


Regards,
Rushikesh Vartak
If you find the response useful, kindly consider selecting Accept As Solution and clicking on the kudos button.

Please find attached

Does JSON configuration done 


Regards,
Rushikesh Vartak
If you find the response useful, kindly consider selecting Accept As Solution and clicking on the kudos button.

sandeepgudipudi
New Contributor III
New Contributor III

Json for MFA? nothing stated as such in document.

However i did configured okta for MFA and still it did not prompt for MFA