Symptom
- In an SSO flow using a Central Login Page, after the user authenticates with a passkey (Webauthn/FIDO), the child site prompts two-factor authentication (TFA) upon redirect.
- TFA is not requested on the Central Login Page during sso.continue, but is requested by the child site after redirect.
- This occurs when Risk-Based Authentication is configured to require TFA on device or country change.
Read more...
Environment
- SAP Customer Data Cloud
- Risk-Based Authentication (RBA)
- Single Sign-On (SSO)
Product
SAP Customer Data Cloud all versions
Keywords
tfa, two-factor, rba, risk-based authentication, passkey, webauthn, fido, clp, central login page, child site, sso.login, sso.continue, device change, country change, session domain, Gigya , KBA , CEC-PRO-PNS , Privacy & Safety (Consent, RBA - Risk-Based Authentication) , Known Error
About this page
This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).Search for additional results
Visit SAP Support Portal's SAP Notes and KBA Search.
SAP Knowledge Base Article - Preview