Multi-factor Authentication (MFA) behaviours and considerations
Who is this article for?
Administrators who want to turn on additional security for the organisation's login process
Admin Console access is required
Multi-Factor Authentication (MFA) improves security for users with internal authentication on Mazlan Home but does not apply to those using external Single Sign-On (SSO) providers.
This article outlines MFA behaviour in Mazlan Home, covering design features, current platform limitations, planned enhancements, and recommended workarounds.
Email MFA behaviours
Password recovery and reset
Users with email as their only MFA method cannot use the standard "Forgot password" or "Reset password" process because both reset and MFA codes are sent to the same email, causing conflicts.
For security, these users must contact their Tenant Administrator to reset the password and receive a temporary one. They can then sign in and set a new password.
The table below details password recovery and reset behaviours for Email MFA in Mazlan Home.
| Behaviour | Remarks |
| Users with Email MFA enabled cannot change their password directly from Profile Settings. | Email MFA users must contact their Tenant Administrator to reset their password instead of using the self-service "Change Password" option. |
| The Forgot Password link is not available on the sign-in screen for organisations with Email MFA enabled. | Email MFA users must contact their Tenant Administrator to reset passwords instead of using the self-service "Forgot Password" option. |
| Each time a Tenant Administrator triggers a Welcome Email, it includes a new temporary password. The user will be prompted with a forced password change the next time they sign in. |
This is expected behaviour. Email MFA users cannot perform a self-service reset, so the Tenant Administrator verifies the request before issuing a new password. The forced password change at next sign-in ensures the temporary password is not used permanently and only the user knows their final password. |
Authenticator app MFA behaviours
Setting up and enrolment
Authenticator App MFA requires users to register by scanning the QR code or entering the secret key before use. Users who haven't completed this cannot sign in.
| Behaviour | Remarks |
| When Authenticator App MFA is enabled for the organisation, users are prompted with the authenticator app setup instructions before their first sign-in. | This is expected behaviour. Tenant Administrators don't need separate setup instructions but may want to remind users to complete Authenticator App setup before signing in. |
| Authenticator Apps MFA must be enabled on its own and cannot be enabled alongside Email MFA per organisation. | Support for mixed MFA per organisation is planned for a future update. Until then, the only option is to enforce a single MFA method for the entire organisation. |
Overriding MFA per user
If you need to exempt a specific user from Email MFA, you can disable it on a per-user basis. TOTP MFA, however, cannot be disabled per user.
| Limitation | Workaround |
| When Authenticator App MFA is enabled for the organisation, the MFA settings for the user cannot be changed. | Support for per-user overrides for Authenticator App is planned for a future update. Until then, there is no known workaround except to enforce that the entire organisation uses a single MFA method. |