<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Topics tagged with multi-factor]]></title><description><![CDATA[A list of topics that have been tagged with multi-factor]]></description><link>https://fusionauth.io/community/forum/tags/multi-factor</link><generator>RSS for Node</generator><lastBuildDate>Fri, 09 Oct 2026 00:42:03 GMT</lastBuildDate><atom:link href="https://fusionauth.io/community/forum/tags/multi-factor.rss" rel="self" type="application/rss+xml"/><pubDate>Invalid Date</pubDate><ttl>60</ttl><item><title><![CDATA[Can I enforce MFA on login for some users but allow step-up MFA for all users?]]></title><description><![CDATA[<p dir="auto">Yes, this is possible with some configuration adjustments.</p>
<p dir="auto">The key insight is that you can use an <strong>MFA requirement lambda</strong> to selectively enforce MFA during login based on user attributes (like a user type or role), while still allowing all users to participate in step-up authentication flows later. The <a href="https://fusionauth.io/docs/extend/code/lambdas/mfa-requirement" rel="nofollow ugc">MFA requirement lambda</a> is an enterprise plan feature.</p>
Recommended Approach

<strong>Configure MFA methods for all users</strong> (both staff and non-staff), but differentiate their login behavior using an MFA requirement lambda
<strong>Set the tenant MFA login policy</strong> to something like Required or Enabled
<strong>Create an MFA requirement lambda</strong> that:

Returns true (require MFA) for staff users
Returns false (skip MFA) for other user types during login



<p dir="auto">This way:</p>

Staff users will be challenged for MFA on every login
Non-staff users will skip MFA during login but still have MFA methods configured
All users can participate in step-up authentication flows when your application calls the step-up APIs, because they all have MFA methods available

Example Lambda Logic
function checkRequired(result, user, registration, context) {

  // assumes there's a role assigned to the user registration. could also examine other attributes or make a fetch call
  var userRoles = registration &amp;&amp; registration.roles || [];
  if (userRoles.includes('staff')) {
     result.required = true;
  } else {
     result.required = false;
  }
}

<p dir="auto">This approach delegates the step-up authentication flow and code sendout completely to FusionAuth while maintaining your login MFA requirements.</p>
]]></description><link>https://fusionauth.io/community/forum/topic/3193/can-i-enforce-mfa-on-login-for-some-users-but-allow-step-up-mfa-for-all-users</link><guid isPermaLink="true">https://fusionauth.io/community/forum/topic/3193/can-i-enforce-mfa-on-login-for-some-users-but-allow-step-up-mfa-for-all-users</guid><dc:creator><![CDATA[FASupportBot]]></dc:creator><pubDate>Invalid Date</pubDate></item></channel></rss>