Sadid Technology & Digital Transformation Group

Sadid MFA

SADID MFA / IDENTITY SECURITY

Trusted identity.
Controlled access.

Sadid multi-factor authentication

Access to organizational applications is protected by a verification step independent of the password. The requester’s identity is checked before access is granted.

The sign-in experience
User verification · Enterprise access protection
Trusted identity. Controlled access.
Security is established through identity verification

Another layer for the access that matters

WorkforceBusiness applicationsOnline services
Trusted identity. Controlled access.
Identity is verified at sign-in.
THE LOGIN EXPERIENCE

A quick confirmation.
Before access.

Once sign-in is initiated, identity is checked using the assigned method. This stage is tailored to each user group.

1Sign-in is initiated
2Identity is verified with a second factor
3Access is granted after verification
Verification methods
AUTHENTICATION METHODS

Different situations. Different ways to verify.

The verification steps and implementation considerations are displayed for each selected situation.

Trusted identity. Controlled access.
THE USER JOURNEY

The request is reviewed before approval

The sign-in request is displayed on the phone and is approved or denied after review. Everyday verification is completed on the same device.

  1. The request is opened
  2. Sign-in details are reviewed
  3. The request is approved or denied
Final method selection and application compatibility are established during technical assessment and the pilot.
BEYOND PASSWORDS

When a sign-in needs more assurance

The role of the second factor and supporting actions are examined across four common situations.

The password is correct.
But is this the right person?

If someone else obtains a password, signing in should not depend on knowing that password alone.

Independent evidence.
Before access continues.

Another factor is required, and its type is selected according to organizational policy.

FOLLOW-UP

The exposed password is reset and the account’s active sessions are reviewed.

1

A sign-in notification has been received without a legitimate request.

An unsolicited request is a reason to pause and investigate.

Rejection of an unrecognized request is enabled through mobile push.

Recommended action

The unrecognized request is denied and reported to support so its origin can be investigated.

2

Access to sensitive information has been assigned to this account.

An appropriate assurance level is determined for each account.

Verification is selected according to role and application sensitivity.

Recommended action

Permissions are limited to what is required and account access is reviewed periodically.

3

A colleague changes roles or leaves.

Access is adjusted when responsibilities are changed.

Enrolled factors and available sign-in paths must be reviewed.

Recommended action

Previous access and sessions are revoked through the role-change or offboarding process.

MFA is part of layered protection, alongside access policy, user guidance and incident handling.

IT MANAGEMENT

A unified view.
More deliberate control.

MFA is incorporated into identity management alongside single sign-on, access policies and event review.

  • In-scope users and applications are identified
  • Verification methods are assigned to user groups
  • Support and access recovery are planned
Trusted identity. Controlled access.
IDENTITY ARCHITECTURE

MFA within the wider security architecture

User identity and role

Eligibility to begin sign-in is determined by the identity source, account status and organizational role.

Verification policy

Verification methods and conditions are defined around the user group and access sensitivity.

Target application

After identity verification, authorization for individual operations must still be enforced by the application.

Events and response

Unusual requests and sign-in problems are investigated through the recording and review of relevant events.

Identity is checked through authentication; permitted operations are determined through authorization. Both are included in the design.

ORGANIZATIONAL CONTEXT

Access scenarios are defined around the working environment

Trusted identity. Controlled access.
Enterprise access, from headquarters to operations
1

Public organizations

Employees, contractors and external users need clearly separated roles when accessing internal services.

Group separation and access lifecycle reviews
2

Financial services

Sensitive accounts and online service access should be evaluated against each application’s security requirements.

Verification assessment for sensitive access
3

Education

Enrollment and support are planned with additional attention to changing user populations and device diversity.

Factor enrollment and temporary user management
4

Manufacturing

Shift workers, remote sites and connectivity constraints require appropriate sign-in scenarios.

Connectivity, device and operational assessment
DEPLOYMENT & OPERATIONS

From infrastructure assessment to a controlled rollout

The sign-in journey is evaluated on a limited scale before broad activation.

A successful deployment extends beyond enabling a security setting. Application compatibility, user readiness, recovery procedures and support responsibilities should be clear from the outset.

Trusted identity. Controlled access.
1

Assessment and scope definition

Applications, user groups, devices and network conditions are inventoried. Sensitive access is prioritized.

Output: rollout scope and acceptance criteria
2

Policy design and pilot

Verification, enrollment and recovery are tested with a small group. Sign-in failures and support requirements are reviewed.

Output: validated policy and pilot findings
3

Phased rollout

Subsequent groups are onboarded with communication and guidance. The support path is defined.

Output: activation plan and user guidance
4

Review and improvement

Policies and operational procedures are reviewed against events, user feedback and application changes.

Output: improvements and periodic review
Trusted identity. Controlled access.
ACCESS CONTINUITY & SUPPORT

Access recovery is
part of security design.

Recovery procedures for lost phones, replacement devices and unavailable factors are defined and communicated before rollout.

  1. Identity is reverified through an approved organizational process
  2. The previous factor is revoked and related access is reviewed
  3. The new factor is enrolled and the account owner is notified
EVALUATION GUIDE

Technical and operational questions

Technical and operational questions are addressed before selection and deployment.

How do MFA and 2FA differ?

In MFA, two or more independent factor categories are used. In two-factor authentication, two factors are applied.

Does every method need internet access?

After enrollment, TOTP codes are generated offline. Network access may still be required by the destination application. Mobile push is delivered over a network connection.

What if a user loses their phone?

Recovery must be defined in advance: identity is reverified, the previous factor is disabled and a new one is enrolled under organizational policy.

Can every application be connected?

Integration depends on the application’s protocols, version and architecture. Compatibility should be verified during assessment and the pilot.

Does MFA replace authorization controls?

No. Verifying identity does not authorize every operation. Data and action permissions must be enforced separately according to user roles.

What should the pilot evaluate?

Enrollment, successful and failed sign-ins, connectivity constraints, device replacement, recovery and support must be evaluated with a representative user group.

Do two passwords count as two factors?

No. Two pieces of evidence from one category are not necessarily accepted as two independent factors. Passwords and security questions are classified as knowledge factors.

Authentication requirements are reviewed in a consultation.

A consultation request can be submitted for an organizational assessment.

SADID MFA JOURNAL

Latest articles