Multi-Factor Authentication (MFA)
Add an extra layer of security to your Strike Graph login with multi-factor authentication
Written By Micah
Multi-factor authentication (MFA) adds a second layer of verification to the login process, requiring users to confirm their identity with a one-time passcode (OTP) in addition to their password. Enabling MFA for your Strike Graph organization helps protect your compliance data from unauthorized access, even if a user's password is compromised. MFA is available on all Strike Graph plans and can be enabled for your organization by contacting support.
How MFA works in Strike Graph
Once MFA is enabled for your organization, every user will be prompted to set up a one-time passcode (OTP) authenticator the next time they log in. After initial setup, users will need to provide a passcode from their authenticator app each time they sign in. Strike Graph's MFA works with any standard OTP authenticator app, including:
Google Authenticator
Microsoft Authenticator
Duo
1Password
Authy
Any app that supports time-based one-time passwords (TOTP) will work.
Enabling MFA for your organization
MFA is not a self-service setting. To enable MFA for your organization, contact your Customer Success Manager or reach out to the support team through the in-app messenger. The Strike Graph team will enable the feature for your organization, and no additional configuration is required on your end. Once enabled, MFA applies to all users in your organization. The next time each user logs in, they will be guided through the setup process to link their authenticator app.
Setting up your authenticator app
When a user logs in for the first time after MFA has been enabled, they will see a setup screen with a QR code. To complete setup:
Open your preferred authenticator app on your phone.
Scan the QR code displayed on the Strike Graph login screen.
Enter the one-time passcode shown in the authenticator app to confirm the link.
After this initial setup, the authenticator app will generate a new passcode every 30 seconds. Users will enter the current passcode each time they log in to Strike Graph.
Resetting MFA tokens
If a user loses access to their authenticator app (for example, because they got a new phone or deleted the app), their MFA token will need to be reset so they can set up a new one. MFA resets are handled by the Strike Graph support team and follow a verification process to protect your account security. The reset process requires two points of contact: the user who lost access must reach out to support, and the primary account holder (or an organization administrator) must separately confirm the reset request. This ensures that multiple people within your organization are verifying the request before MFA is removed from an account. To request an MFA reset:
The locked-out user should contact Strike Graph support through email or the in-app messenger and request an MFA reset.
The primary account holder or an organization administrator must separately confirm the reset request with the Strike Graph support team.
Once both contacts have been verified, the Strike Graph team will reset the user's MFA enrollment.
The user can then log in again and will be prompted to set up a new authenticator app, following the same QR code setup process as before.
This two-contact verification requirement is a security measure to prevent unauthorized MFA resets.
MFA and SSO
If your organization uses Single Sign-On (SSO), MFA enforcement at the Strike Graph level may not be necessary, since your identity provider likely already enforces its own multi-factor authentication policies. However, the two features are independent: you can use SSO with or without Strike Graph's MFA enabled, depending on your security requirements. If you are unsure whether to enable MFA alongside SSO, your Customer Success Manager can help you decide based on your organization's setup.
Need help?
To enable MFA for your organization, reset an MFA token, or ask any questions about authentication options, reach out to your Customer Success Manager or contact support through the in-app messenger.