Multi-Factor Authentication (MFA)
Multi-Factor Authentication (MFA) adds a second layer of security to the Zentra login process. When MFA is required for a site, users must verify their identity with an additional method every time they log in to the Zentra web app or mobile app.
MFA is a
login security
feature. It controls who can access the Zentra application. It is separate from any door-level access rules configured on your site.
Requirements
- The feature is currently only available to sites that have an wallet based credential-enabled license
- MFA is controlled at the tenant level by administrators and integrators. Individual users cannot enable or disable it.
MFA is
required
in order to use wallet-based credentials. When this feature is added to a site, MFA is enabled automatically — this is an Apple requirement and cannot be removed.
How It Works
- An administrator or integrator enables MFA in the site’s Global Settings (or it is enabled automatically when wallet based credentials are configured for the site).
- An email notification is sent to all users of the site.
- The next time each user logs in, they are directed to a setup page and must enroll in an MFA method before they can access the site.
- Once enrolled, users complete their chosen verification step each time they log in.
Once MFA is enabled for a site, it
cannot be turned off
.
Verification Methods
Users can enroll in one of the following methods:
Method | Description |
|---|---|
Authenticator App PIN | A time-based one-time code from an authenticator app such as Google Authenticator or Microsoft Authenticator. |
Biometrics | Device fingerprint or face recognition. See the note below about how biometrics interact with your login method. |
Email PIN | A verification code sent to your registered email address. Always available as a fallback. |
Email is always available as a backup verification method, even if another method is enrolled.
Biometrics — Important Note
Biometrics (fingerprint or face ID) can be used either as your
login method
(replacing your password) or as your MFA verification method
— but not both at the same time.- If you log in with yourusername and password, you can use biometrics as your MFA second factor.
- If you log in withbiometrics instead of your password, you will need a separate second factor for MFA. If biometrics is your only enrolled MFA method, you will be required to use email as your MFA fallback instead.