Verifying your identity with multi-factor authentication in Identity360

When multi-factor authentication (MFA) is required, Identity360 asks you to confirm your identity with one of the methods in which you have enrolled. This happens when you sign in to the Identity360 portal or a cloud application and, if your organization uses Identity Access, when you sign in to a computer or endpoint it protects. This guide explains how to verify your identity with each method and what to do when your usual method is unavailable.

Verifying your identity with each method

At the verification prompt, choose one of your enrolled methods and complete it:

  • Email Verification: Enter the one-time code sent to your primary or chosen email address within the time limit shown.
  • SMS Verification: Enter the one-time code sent by text to your mobile number within the time limit shown.
  • Google Authenticator, Microsoft Authenticator, or Zoho OneAuth TOTP: Enter the current code from the app.
  • Custom TOTP Authenticator: Enter the current code from your organization's TOTP authenticator.
  • FIDO2 Passkeys: Use your device's built-in authentication system (Windows Hello, Touch ID, Face ID, or a device PIN) or your security key.
  • Duo: Approve the request in Duo, then return to Identity360.
  • Logins via other apps: If this is enabled, verify your identity by signing in through Microsoft Entra ID or Salesforce.

If you cannot use your usual method

  • Backup Verification Codes: At the prompt, choose the Backup Verification Code option and enter one of the one-time codes you generated earlier.
  • Emergency Access Code: If you are locked out, ask your administrator for a single-use Emergency Access Code.

Reducing how often you are asked

Depending on your organization's policy, you can choose to verify your identity less often on devices you use regularly:

  • Trust this browser: Select this at the prompt to skip MFA in the same browser for the number of days set by your administrator.
  • Trust this machine: After you verify your identity successfully, skip further prompts on that machine according to your policy.
Note: After several failed attempts, you may be asked to complete a CAPTCHA before you can try again.

Tips

  • Enroll in a second method so you can still verify your identity if your usual method is unavailable.
  • Trust a browser or machine only on devices that you control and that are not shared.