MFA for Mobile App Users
DRAFT: UNDER REVIEW
When MFA is required for a site, Zentra Mobile App users are prompted to enroll or verify when accessing that site.
Site Selection Screen
Sites that require MFA display an indicator icon next to the site name on the site selection screen.
Single-Site Users
If you only have access to one site and it requires MFA:
- Open the Zentra Mobile App and log in.
- If you have not yet enrolled in MFA, you will be taken directly to the MFA setup screen. You cannot proceed until enrollment is complete.
- Follow the on-screen steps to set up your verification method.
- Once enrolled, you are taken to the app.
Multi-Site Users
If you have access to more than one site:
- Log in and navigate to the site selection screen.
- Tap a site that requires MFA.
- If you have not yet enrolled, you will be guided through the MFA enrollment flow.
- If you are already enrolled, you will be prompted to verify with your MFA method.
- Once verified, you are taken to that site.
Verification Methods on Mobile
Method | Notes |
Authenticator App PIN | Works offline once the authenticator app is configured. |
Biometrics | Uses the device’s built-in fingerprint or face hardware. See the biometrics note on the overview page. |
Email PIN | Always available as a fallback. Requires an internet connection. |
If you log into the mobile app using biometrics as your password, and biometrics is also your only enrolled MFA method, you will be required to use email as your MFA fallback.
MFA and Wallet-Based Credentials (Resident Key)
MFA is required in order to use wallet-based credentials. If MFA is not set up on your account, you will not be able to add your Resident Key to Apple Wallet or Google Wallet.
Known Behavior
Setting up a trusted device (passkey or device fingerprint) and enrolling in MFA are two separate flows. If you are prompted to set up MFA after completing a trusted device setup, this is expected — complete the MFA enrollment to proceed.