<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Can I enforce MFA on login for some users but allow step-up MFA for all users?]]></title><description><![CDATA[<p dir="auto">I'm trying to configure a FusionAuth setup where:</p>
<ul>
<li><strong>Staff users</strong> must use MFA on every login (currently achieved by setting MFA methods for those users) <img src="https://fusionauth.io/community/forum/assets/plugins/nodebb-plugin-emoji/emoji/android/2705.png?v=rcgg4tg866g" class="not-responsive emoji emoji-android emoji--white_check_mark" style="height:23px;width:auto;vertical-align:middle" title=":white_check_mark:" alt="✅" /></li>
<li><strong>Other user types</strong> should NOT be prompted for MFA on login (currently achieved by not setting MFA methods for those users) <img src="https://fusionauth.io/community/forum/assets/plugins/nodebb-plugin-emoji/emoji/android/2705.png?v=rcgg4tg866g" class="not-responsive emoji emoji-android emoji--white_check_mark" style="height:23px;width:auto;vertical-align:middle" title=":white_check_mark:" alt="✅" /></li>
<li>The tenant's MFA login policy is set to: <code>Enabled: Only challenge if user has configured an eligible MFA method</code></li>
</ul>
<p dir="auto">However, I also want to support <strong>step-up authentication</strong> for all users (including those without MFA methods configured), where my application can trigger a code to be sent via FusionAuth during sensitive operations.</p>
<p dir="auto">Based on the API docs for <a href="https://fusionauth.io/docs/apis/two-factor/start-multi-factor" rel="nofollow ugc">start-multi-factor</a> and <a href="https://fusionauth.io/docs/apis/two-factor/send-a-multi-factor-code-during-login-or-step-up" rel="nofollow ugc">send-a-multi-factor-code-during-login-or-step-up</a>, it appears that users must have MFA methods configured to use the step-up flow.</p>
<p dir="auto"><strong>Question:</strong> Is there a way to leverage an MFA requirement lambda combined with an MFA login policy to:</p>
<ol>
<li>Enforce MFA on login only for staff users</li>
<li>Allow step-up MFA flows (with code generation and sendout) for all users, even those without MFA methods configured at login time?</li>
</ol>
]]></description><link>https://fusionauth.io/community/forum/topic/3193/can-i-enforce-mfa-on-login-for-some-users-but-allow-step-up-mfa-for-all-users</link><generator>RSS for Node</generator><lastBuildDate>Fri, 09 Oct 2026 01:09:56 GMT</lastBuildDate><atom:link href="https://fusionauth.io/community/forum/topic/3193.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 02 Oct 2026 23:41:59 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Can I enforce MFA on login for some users but allow step-up MFA for all users? on Thu, 08 Oct 2026 12:54:24 GMT]]></title><description><![CDATA[<p dir="auto">Yes, this is possible with some configuration adjustments.</p>
<p dir="auto">The key insight is that you can use an <strong>MFA requirement lambda</strong> to selectively enforce MFA during login based on user attributes (like a user type or role), while still allowing all users to participate in step-up authentication flows later. The <a href="https://fusionauth.io/docs/extend/code/lambdas/mfa-requirement" rel="nofollow ugc">MFA requirement lambda</a> is an enterprise plan feature.</p>
<h2>Recommended Approach</h2>
<ol>
<li><strong>Configure MFA methods for all users</strong> (both staff and non-staff), but differentiate their login behavior using an MFA requirement lambda</li>
<li><strong>Set the tenant MFA login policy</strong> to something like <code>Required</code> or <code>Enabled</code></li>
<li><strong>Create an MFA requirement lambda</strong> that:
<ul>
<li>Returns <code>true</code> (require MFA) for staff users</li>
<li>Returns <code>false</code> (skip MFA) for other user types during login</li>
</ul>
</li>
</ol>
<p dir="auto">This way:</p>
<ul>
<li>Staff users will be challenged for MFA on every login</li>
<li>Non-staff users will skip MFA during login but still have MFA methods configured</li>
<li>All users can participate in step-up authentication flows when your application calls the step-up APIs, because they all have MFA methods available</li>
</ul>
<h2>Example Lambda Logic</h2>
<pre><code class="language-javascript">function checkRequired(result, user, registration, context) {

  // assumes there's a role assigned to the user registration. could also examine other attributes or make a fetch call
  var userRoles = registration &amp;&amp; registration.roles || [];
  if (userRoles.includes('staff')) {
     result.required = true;
  } else {
     result.required = false;
  }
}
</code></pre>
<p dir="auto">This approach delegates the step-up authentication flow and code sendout completely to FusionAuth while maintaining your login MFA requirements.</p>
]]></description><link>https://fusionauth.io/community/forum/post/8723</link><guid isPermaLink="true">https://fusionauth.io/community/forum/post/8723</guid><dc:creator><![CDATA[FASupportBot]]></dc:creator><pubDate>Thu, 08 Oct 2026 12:54:24 GMT</pubDate></item></channel></rss>