THANK YOU FOR SUBSCRIBING
Enterprise Security Magazine | Thursday, December 24, 2020
Adaptive MFA is designed to help businesses overcome the inherent challenges of enabling protection while retaining user experience.
FREMONT, CA: Auth0, an identity network for application teams, introduced Adaptive Multi-factor Authentication (MFA), a sophisticated security feature that helps reduce the possibility of hacks and data breaches. Adaptive MFA is a significant addition to Auth0’s broader security portfolio—including Bot Detection, Breached Password Detection, Brute Force Protection, and Suspicious IP Throttling—and is one of the platform’s most innovative context-based security features.
“Auth0’s mission is to provide secure access for everyone. Securing identities is core to that mission and this new capability adds to the already powerful features in our security profile, designed to counter a variety of sophisticated threats, such as automated attacks, account takeovers, and phishing attacks,” said Shiven Ramji, Chief Product Officer, Auth0. “Adaptive MFA should be a key consideration for any enterprise that has previously had to make a tradeoff between security and user experience. The ability to reduce friction while increasing security is a competitive differentiator for our customers.”
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
Adaptive MFA is designed to help businesses overcome the inherent challenges of enabling protection while retaining user experience. Unlike conventional MFA, which is activated at any login attempt and creates an additional phase for the end-user, Adaptive MFA only occurs when the login is perceived to be risky. This aspect is determined by the overall risk score, which tests known devices' abnormal activity, the inability to travel, and IP credibility. Customers should be assured that with Adaptive MFA, their end-users will only be asked for secondary authentication if the behavioral signals do not adhere to the standard patterns for a specific user.
For instance, for a user who usually logs in to their account at the same time every morning in San Francisco from a personal laptop, Adaptive MFA will only present a second authenticator if an attempt was made to log in outside the area, the standard timeframe, or from a different device or IP address. Developers may decide how much weight each signal is assigned to identify the risk score that activates the trigger.
Many businesses are reluctant to adopt MFA—proven to be adequate protection against account hacking attacks—out of fear of adversely affecting user experience and their conversion and retention results. However, additional friction during sign-up, login, or check-out interactions may affect customers' conversion/retention, resulting in lost sales and may potentially increase support accidents. Forrester estimates that the MFA market will grow to 2 billion dollars by 2023, and this projected growth suggests the need for a more intelligent and context-based MFA solution.
More in News