Multi-Factor Authentication (MFA) for KP Users
Overview
The Multi-Factor Authentication (MFA) feature adds an additional layer of security to Keen Platform (KP) user accounts by requiring a time-based verification code during login.
MFA can be enabled at the user level or enforced at the company or agency level, ensuring compliance with security requirements and protecting account access.
How MFA Works
MFA introduces a second authentication step after a user enters their credentials. Users must provide a 6-digit verification code generated by an authenticator app (e.g., Google Authenticator or Microsoft Authenticator).
There are three ways MFA can be applied:
User-Enabled MFA (Optional / Self-Service)
A user turns on MFA themselves from their profile settings.
Company-Enforced MFA
MFA is required for all users associated with a specific company.
Set by Company Admins or Keen Admins.
Agency-Enforced MFA
MFA is required for all users associated with companies under a specific agency.
Set at the agency level and cascades down.
Navigation
MFA is only an option for paid plans, and settings and visibility can be accessed from:
User Admin
Can view MFA status per user
Can reset MFA (Keen Admin only)
My Profile
Users can enable or disable MFA (if not enforced)
Company Settings (Segment Admin)
Users can enable or disable MFA requirement at the company level
Agency Settings (Agency Admin)
Users can enable or disable MFA requirement at the agency level
MFA Setup Flow
When MFA is enabled (manually or via enforcement), users are guided through a setup process upon next login.
Step 1: Authenticator Setup
Users download an authenticator app and scan a QR code or enter a manual key.
Step 2: Recovery Codes
Users must download or copy recovery codes. These are required to regain access if the authenticator device is unavailable.
Step 3: Verification
Users enter a 6-digit code from their authenticator app to complete setup.
Login Behavior After Setup
Once MFA is configured:
Users enter their credentials as usual
Users are prompted to enter a 6-digit authentication code
Alternatively, users may enter a recovery code
Each Sign in after set up should appear as:
With too many failed attempts you may receive an error message:
Recovery Code Usage
If a user cannot access their authenticator app:
A recovery code can be entered during login
Recovery codes are generated during setup and must be stored securely
Company-Level MFA Enforcement
How it Works
When MFA is enabled at the company level:
All non-Keen Admin users associated with the company must use MFA
User-level MFA settings become locked
MFA is automatically enabled for all applicable users
Confirmation Requirement
Enabling MFA at the company level will cause:
A confirmation Pop-up explaining the impact
Typing “CONFIRM” allows the user to proceed
Agency-Level MFA Enforcement
How it Works
When MFA is enabled at the agency level:
All users tied to companies under that agency must use MFA
Enforcement cascades down to all associated users
2FMA will appear as a column in the agency table. 2MFA Required: Yes, No
Email Notifications
MFA Enabled
When MFA is enabled, an email alert prompts user to complete setup
This email includes CTA to begin MFA setup
MFA Disabled
If MFA is disabled an email alert notifies user MFA has been turned off
This email includes support instructions if unauthorized
MFA Reset
If MFA is resent, an email alert informs user MFA has been reset
This reset requires reconfiguration
Account Locked
If the account is locked, an email alert notifies user of lockout due to failed attempts
This alert provides recovery option
Best Practices & Implementation Notes
Enforce MFA at the company or agency level for consistent security coverage
Ensure users securely store recovery codes during setup
Use MFA reset cautiously, as it requires full reconfiguration by the user
Communicate enforcement changes clearly to avoid login disruptions
For additional guidance on tailoring your approach, consult your Keen account manager.