Multi-factor Authentication (MFA) behaviours and considerations
Who is this article for?
Administrators who want to turn on additional security for the organisation's login process
Admin Console access is required
Multi-Factor Authentication (MFA) improves security for users with internal authentication on Mazlan Home but does not apply to those using external Single Sign-On (SSO) providers.
This article outlines MFA behaviour in Mazlan Home, covering design features, current platform limitations, planned enhancements, and recommended workarounds.
Email MFA behaviours
Password recovery and reset
Users with email as their only MFA method cannot use the standard "Forgot password" or "Reset password" process because both reset and MFA codes are sent to the same email, causing conflicts.
For security, these users must contact their Tenant Administrator to reset the password and receive a temporary one. They can then sign in and set a new password.
The table below details password recovery and reset behaviours for Email MFA in Mazlan Home.
| Behaviour | Remarks |
| Users with Email MFA enabled cannot change their password directly from Profile Settings. | Email MFA users must contact their Tenant Administrator to reset their password instead of using the self-service "Change Password" option. |
| The Forgot Password link is not available on the sign-in screen for organisations with Email MFA enabled. | Email MFA users must contact their Tenant Administrator to reset passwords instead of using the self-service "Forgot Password" option. |
| Each time a Tenant Administrator triggers a Welcome Email, it includes a new temporary password. The user will be prompted with a forced password change the next time they sign in. |
This is expected behaviour. Email MFA users cannot perform a self-service reset, so the Tenant Administrator verifies the request before issuing a new password. The forced password change at next sign-in ensures the temporary password is not used permanently and only the user knows their final password. |
Authenticator app MFA behaviours
Setup and enrolment
Authenticator App MFA requires users to register by scanning the QR code or entering the secret key before use. Users who haven't completed this cannot sign in.
| Behaviour | Remarks |
| When Authenticator App MFA is enabled for the organisation, users are prompted with the authenticator app setup instructions before their first sign-in. | This is intended behaviour. Tenant Administrators don't need to write separate setup instructions, but may still want to remind users that completing Authenticator App setup is required before they can sign in. |
| uthenticator Apps MFA must be enabled on its own and cannot be enabled alongside Email MFA per organisation. | Support for mixed-MFA per organisation is planned for a future update. Until then, there is no known workaround except to enforce that the entire organisation uses a single MFA method. |
Overriding MFA per user
If you need to exempt a specific user from Email MFA, you can disable it on a per-user basis. TOTP MFA, however, cannot be disabled per user.
| Limitation | Workaround |
| When Authenticator App MFA is enabled for the organisation, the MFA settings for the user cannot be changed. | Support for per-user overrides for Authenticator App is planned for a future update. Until then, there is no known workaround except to enforce that the entire organisation uses a single MFA method. |