Yes, this is possible with some configuration adjustments.

The key insight is that you can use an MFA requirement lambda to selectively enforce MFA during login based on user attributes (like a user type or role), while still allowing all users to participate in step-up authentication flows later. The MFA requirement lambda is an enterprise plan feature.

Recommended Approach Configure MFA methods for all users (both staff and non-staff), but differentiate their login behavior using an MFA requirement lambda Set the tenant MFA login policy to something like Required or Enabled Create an MFA requirement lambda that: Returns true (require MFA) for staff users Returns false (skip MFA) for other user types during login

This way:

Staff users will be challenged for MFA on every login Non-staff users will skip MFA during login but still have MFA methods configured All users can participate in step-up authentication flows when your application calls the step-up APIs, because they all have MFA methods available Example Lambda Logic function checkRequired(result, user, registration, context) { // assumes there's a role assigned to the user registration. could also examine other attributes or make a fetch call var userRoles = registration && registration.roles || []; if (userRoles.includes('staff')) { result.required = true; } else { result.required = false; } }

This approach delegates the step-up authentication flow and code sendout completely to FusionAuth while maintaining your login MFA requirements.