Okta Adaptive Multi-Factor Authentication Versus Standard Multi-Factor Authentication
Last Updated:
Overview
Adaptive Multi-Factor Authentication (AMFA) functions as an intelligent security layer that Okta builds on top of standard Multi-Factor Authentication (MFA) to assess the context and risk of each login attempt in real-time. Okta applies authentication requirements dynamically by removing friction for low-risk users while stepping up security for high-risk access attempts.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Adaptive Multi-Factor Authentication (AMFA)
- Multi-Factor Authentication (MFA)
Solution
What are the core capabilities of Okta Adaptive Multi-Factor Authentication?
Review the following list to understand the core capabilities that Adaptive Multi-Factor Authentication (AMFA) includes to secure authentication flows.
- Behavior Detection: Compares incoming login requests against a historical baseline. By analyzing past authentication patterns, Okta automatically flags unusual activity. Okta monitors patterns such as typical IP addresses, geographic locations, and devices that the individual uses. If a user normally logs in from an office in New York on a specific laptop, an access attempt from a new device in another country triggers a higher risk score.
- Risk Detection Engine: Uses an array of security signals and external threat intelligence to calculate a real-time confidence score for every login. Okta evaluates threats using the following signals.
- Velocity / Impossible Travel: Detects if a user logs in from two geographically distant locations in an impossibly short timeframe.
- Reputation Scoring: Analyzes the reputation of the IP address, email, and domain (e.g., flagging known malicious IPs or anonymizing proxies).
- Breached Password Detection: Identifies if known data breaches compromised the provided credentials.
- Dynamic Zones: Allow administrators to define specific network perimeters and locations to govern access based on where a request originates. Okta uses IP ranges, geolocations, and proxies to evaluate context. Administrators configure rules to instantly block traffic from embargoed countries or bypass MFA for users authenticating from a trusted corporate network.
- Device Context and Integrations: Assesses the security posture and familiarity of the device attempting access. Okta evaluates device history and integrates directly with Certificate Authorities and Mobile Device Management (MDM) solutions. Okta checks for device trust and specific device insurance policies before granting access.
- Bot Detection and CAPTCHA: Okta mitigates automated threats like credential stuffing and brute-force attacks before they reach the authentication layer. Okta utilizes massive ecosystem data to recognize bot-like behavior and deploys Completely Automated Public Turing test to tell Computers and Humans Apart (CAPTCHA) and Suspicious IP Throttling to protect the login flow.
Okta Adaptive Multi-Factor Authentication enforces dynamic outcomes based on evaluated signals.
Based on the evaluated signals, AMFA dynamically enforces one of the following actions to manage access.
- Allow (Frictionless): Okta deems the login low-risk and grants access without prompting for a second factor.
- Challenge (Step-Up): Okta detects moderate or high risk and prompts the user to verify their identity using a strong factor (e.g., Okta Verify, Biometrics).
- Block: Okta detects extreme risk or a policy violation (e.g., bad IP reputation or blocked geography) and denies access entirely.
How do the features of standard Multi-Factor Authentication compare to Adaptive Multi-Factor Authentication?
Review the following table to compare the features that standard Multi-Factor Authentication and Adaptive Multi-Factor Authentication provide.
| Multi-factor authentication | MFA | Adaptive MFA |
| Knowledge factors | ||
| Security question | X | X |
|
Possession factors
| ||
| Okta Verify OTP | X | X |
| Okta Verify Push | X | X |
| Okta Verify Push with Number Challenge | - | X |
| Okta FastPass | X | X |
| Email as a factor | X | X |
| SMS | X | X |
| Voice | X | X |
| U2F | X | X |
| Third-party factors | X | X |
| Biometric factors | ||
| Windows Hello | X | X |
| Apple TouchID | X | X |
| Risk-based Authentication | ||
| Location context | ||
| New city, state, or country | - | X |
| New geo-location | - | X |
| Impossible travel patterns | - | X |
| Device context | ||
| New device | - | X |
| Managed device | - | X |
| Device security attributes | - | X |
| Network context | ||
| New IP | - | X |
| Specified IP zones | X | X |
| Network anonymizers | - | X |
| Okta ThreatInsight | X | X |
In addition to the previously listed items, the AMFA feature set enables administrators to create Authenticator Enrollment Policies. Review the Authenticator enrollment policies documentation for more details on these policies.
