Multi-Factor Authentication (MFA)

Multi-Factor Authentication (MFA) adds a second layer of security to the Zentra login process. When MFA is required for a site, users must verify their identity with an additional method every time they log in to the Zentra web app or mobile app.
MFA is a
login security
feature. It controls who can access the Zentra application. It is separate from any door-level access rules configured on your site.
Requirements
  • The feature is currently only available to sites that have an wallet based credential-enabled license
  • MFA is controlled at the tenant level by administrators and integrators. Individual users cannot enable or disable it.
MFA is
required
in order to use wallet-based credentials. When this feature is added to a site, MFA is enabled automatically — this is an Apple requirement and cannot be removed.
How It Works
  1. An administrator or integrator enables MFA in the site’s Global Settings (or it is enabled automatically when wallet based credentials are configured for the site).
  2. An email notification is sent to all users of the site.
  3. The next time each user logs in, they are directed to a setup page and must enroll in an MFA method before they can access the site.
  4. Once enrolled, users complete their chosen verification step each time they log in.
Once MFA is enabled for a site, it
cannot be turned off
.
Verification Methods
Users can enroll in one of the following methods:
Method
Description
Authenticator App PIN
A time-based one-time code from an authenticator app such as Google Authenticator or Microsoft Authenticator.
Biometrics
Device fingerprint or face recognition. See the note below about how biometrics interact with your login method.
Email PIN
A verification code sent to your registered email address. Always available as a fallback.
Email is always available as a backup verification method, even if another method is enrolled.
Biometrics — Important Note
Biometrics (fingerprint or face ID) can be used either as your
login method
(replacing your password) or as your
MFA verification method
— but not both at the same time.
  • If you log in with your
    username and password
    , you can use biometrics as your MFA second factor.
  • If you log in with
    biometrics instead of your password
    , you will need a separate second factor for MFA. If biometrics is your only enrolled MFA method, you will be required to use email as your MFA fallback instead.