About multi-factor authentication
Auth and access
This is an advanced org feature that is only available on the Kinde Scale plan. You can set multi-factor auth for 5 organizations and then charges apply for each organization that uses advanced org features.
As part of being able to set unique authentication methods for an organization, you can also set how multi-factor authentication (MFA) works per organization.
You might want to use MFA for some of your orgs, such as for business customers that require their users to have MFA as part of sign in. This is common in finance and government sectors.
As part of this feature, you can:
If you do not want every organization in your business to use MFA, you must switch off the environment-level requirement.
In Kinde, go to Settings > Environment > Multi-factor auth.
Select No - If you want MFA to be applied in only some organizations or for some connections in your business. You will then need to set MFA in each organization separately.
Select Yes or Optional - If you want everyone, in every organization to use MFA’. Note that if you select Yes here, MFA will apply in all organizations regardless of what you set at the organization level.
This procedure assumes you have switched off the environment-level setting for MFA.
You need to have roles set up in Kinde.
If a user has a mix of exempt and non-exempt roles, MFA will apply as default.
This procedure only works if you have switched off the environment-level setting for MFA. You also need to have enterprise connections set up in Kinde.
If a user signs in via Okta (exempt) and has an Admin role (not exempt), they will not be prompted for MFA.
This procedure only works if you have also switched off the environment-level setting for MFA.
If users are already authenticating via MFA in the organization, switching it off may cause breaking changes.