Building a genuine Client-Initiated Backchannel Authentication demo against a real Guardian push notification - not a simulated approver inbox - turned up two bugs of my own making, then a Rich Authorization Requests upgrade that changes what the push notification is actually allowed to say.
MFA
4 posts.
Running Auth0 MFA demos with real SMS requires every presenter to have a personal phone enrolled. Auth0's custom-phone-provider trigger lets you route codes to a shared inbox instead, so any team member can run the demo without any per-device setup.
When OIE was released it championed assurance levels rather than specific authenticators. This provided a better experience for the majority of users and administrators. This ease of use came at the cost of easily being able to specify specific factors or factor orders which some
MFA, Passwordless and Phishing Resistance are all terms we are hearing more and more lately. MFA usage has nearly doubled since 2020 according to Okta's recent Secure Sign in trends report discussed here Unfortunately there is a lot of confusion around what these terms and more b