SAP Knowledge Base Article - Preview

3709617 - clarification on parameters used in ondevicechange criteria for risk-based authentication

Symptom

A customer is implementing MFA using Risk-Based Authentication (RBA) in SAP Customer Data Cloud and wants to ensure that email verification is performed before allowing MFA (phone number) enrollment.

The customer observes the following behaviour:

  • If a user’s email address is already verified

  • When MFA (Assurance Level 20) is required

  • The user is taken directly to phone number registration

  • No additional email OTP verification is requested before MFA enrollment

The customer asks whether it is possible to:

  • Force email verification again before MFA enrollment


Read more...

Environment

  • SAP Customer Data Cloud (CDC)

  • Risk-Based Authentication (RBA)

  • Email Identity Verification

  • MFA (Phone / SMS / Authenticator App)

Product

SAP Customer Data Cloud all versions

Keywords

SAP Customer Data Cloud, CDC, MFA, RBA, Email Verification, Identity Verification, Assurance Levels, MFA Enrollment, Screen Sets , KBA , CEC-PRO-PNS , Privacy & Safety (Consent, RBA - Risk-Based Authentication) , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.