SAP Knowledge Base Article - Public

3658619 - Enable Transactional Verification for Critical Transactions

Symptom

  • How does the Enable Transactional Verification feature work?
  • Can Multi-Factor Authentication (MFA) be used in scenarios other than login?

"Image/data in this KBA is from SAP internal systems, sample data, or demo systems. Any resemblance to real data is purely coincidental."

Environment

SAP SuccessFactors HCM Suite

Resolution

You can now use Multi-Factor Authentication (MFA) configured in Identity Authentication Services (IAS) not only during login, but also for specific critical transactions within SAP SuccessFactors.
 
MFA can be applied in the following scenarios:
  • Updating payment information in Employee Central (primary use case)
  • Registering new OpenID Connect (OIDC) clients in SAP SuccessFactors (optional scenario, typically used for testing MFA setup)

How to enable this feature?

It is required that the MFA is enabled in IAS and that you have configured in the SuccessFactors Application in IAS, as per guide Multi-Factor Authentication | SAP Help Portal

  1. After enabling the MFA, go to Manage SAML SSO Settings
  2. Select the check box named "Enable Transactional Verification":

After enabling it, once you try to perform any of the scenarios supported above, you should see the pop up box below. For example, when trying to register new OpenID Connect (OIDC) clients:

Then, just enter the MFA code and it allows you to conclude the action.

Important: there is currently an issue with this feature, please check the below article for more information.

See Also

New Option to Enable Transactional Verification for Critical Transactions | SAP Help Portal

Keywords

sf, SSO, 2-Factor Authentication, IAS, multi factor authentication, code , KBA , LOD-SF-PLT-SAM , SAML SSO First Time Setup , Product Enhancement

Product

SAP SuccessFactors HCM Suite 2511