Can I enforce MFA on login for some users but allow step-up MFA for all users?
-
I'm trying to configure a FusionAuth setup where:
- Staff users must use MFA on every login (currently achieved by setting MFA methods for those users)

- Other user types should NOT be prompted for MFA on login (currently achieved by not setting MFA methods for those users)

- The tenant's MFA login policy is set to:
Enabled: Only challenge if user has configured an eligible MFA method
However, I also want to support step-up authentication for all users (including those without MFA methods configured), where my application can trigger a code to be sent via FusionAuth during sensitive operations.
Based on the API docs for start-multi-factor and send-a-multi-factor-code-during-login-or-step-up, it appears that users must have MFA methods configured to use the step-up flow.
Question: Is there a way to leverage an MFA requirement lambda combined with an MFA login policy to:
- Enforce MFA on login only for staff users
- Allow step-up MFA flows (with code generation and sendout) for all users, even those without MFA methods configured at login time?
- Staff users must use MFA on every login (currently achieved by setting MFA methods for those users)
-
Yes, this is possible with some configuration adjustments.
The key insight is that you can use an MFA requirement lambda to selectively enforce MFA during login based on user attributes (like a user type or role), while still allowing all users to participate in step-up authentication flows later. The MFA requirement lambda is an enterprise plan feature.
Recommended Approach
- Configure MFA methods for all users (both staff and non-staff), but differentiate their login behavior using an MFA requirement lambda
- Set the tenant MFA login policy to something like
RequiredorEnabled - Create an MFA requirement lambda that:
- Returns
true(require MFA) for staff users - Returns
false(skip MFA) for other user types during login
- Returns
This way:
- Staff users will be challenged for MFA on every login
- Non-staff users will skip MFA during login but still have MFA methods configured
- All users can participate in step-up authentication flows when your application calls the step-up APIs, because they all have MFA methods available
Example Lambda Logic
function checkRequired(result, user, registration, context) { // assumes there's a role assigned to the user registration. could also examine other attributes or make a fetch call var userRoles = registration && registration.roles || []; if (userRoles.includes('staff')) { result.required = true; } else { result.required = false; } }This approach delegates the step-up authentication flow and code sendout completely to FusionAuth while maintaining your login MFA requirements.
-
D dan has marked this topic as solved