Multi-Factor Authentication (MFA) for KP Users

Multi-Factor Authentication (MFA) for KP Users

Overview

The Multi-Factor Authentication (MFA) feature adds an additional layer of security to Keen Platform (KP) user accounts by requiring a time-based verification code during login.

MFA can be enabled at the user level or enforced at the company or agency level, ensuring compliance with security requirements and protecting account access.

How MFA Works

MFA introduces a second authentication step after a user enters their credentials. Users must provide a 6-digit verification code generated by an authenticator app (e.g., Google Authenticator or Microsoft Authenticator).

There are three ways MFA can be applied:

  • User-Enabled MFA (Optional / Self-Service)

    • A user turns on MFA themselves from their profile settings.

  • Company-Enforced MFA

    • MFA is required for all users associated with a specific company.

    • Set by Company Admins or Keen Admins.

  • Agency-Enforced MFA

    • MFA is required for all users associated with companies under a specific agency.

    • Set at the agency level and cascades down.

image-20260430-134619.png

Navigation

MFA is only an option for paid plans, and settings and visibility can be accessed from:

  • User Admin

    • Can view MFA status per user

    • Can reset MFA (Keen Admin only)

  • My Profile

    • Users can enable or disable MFA (if not enforced)

  • Company Settings (Segment Admin)

    • Users can enable or disable MFA requirement at the company level

  • Agency Settings (Agency Admin)

    • Users can enable or disable MFA requirement at the agency level

MFA Setup Flow

When MFA is enabled (manually or via enforcement), users are guided through a setup process upon next login.

Step 1: Authenticator Setup

Users download an authenticator app and scan a QR code or enter a manual key.

 

Step 2: Recovery Codes

Users must download or copy recovery codes. These are required to regain access if the authenticator device is unavailable.

 

Step 3: Verification

Users enter a 6-digit code from their authenticator app to complete setup.

 

Login Behavior After Setup

Once MFA is configured:

  • Users enter their credentials as usual

  • Users are prompted to enter a 6-digit authentication code

  • Alternatively, users may enter a recovery code

  • Each Sign in after set up should appear as:

image-20260430-135046.png

With too many failed attempts you may receive an error message:

image-20260430-135135.png

Recovery Code Usage

If a user cannot access their authenticator app:

  • A recovery code can be entered during login

  • Recovery codes are generated during setup and must be stored securely

image-20260430-135157.png

Company-Level MFA Enforcement

How it Works

When MFA is enabled at the company level:

  • All non-Keen Admin users associated with the company must use MFA

  • User-level MFA settings become locked

  • MFA is automatically enabled for all applicable users

image-20260430-135440.png

Confirmation Requirement

Enabling MFA at the company level will cause:

  • A confirmation Pop-up explaining the impact

  • Typing “CONFIRM” allows the user to proceed

image-20260430-135458.png
image-20260430-135521.png

Agency-Level MFA Enforcement

How it Works

When MFA is enabled at the agency level:

  • All users tied to companies under that agency must use MFA

  • Enforcement cascades down to all associated users

image-20260430-135729.png
  • 2FMA will appear as a column in the agency table. 2MFA Required: Yes, No

image-20260430-135817.png

 

Email Notifications

MFA Enabled

  • When MFA is enabled, an email alert prompts user to complete setup

  • This email includes CTA to begin MFA setup

image-20260430-140033.png

 

MFA Disabled

  • If MFA is disabled an email alert notifies user MFA has been turned off

  • This email includes support instructions if unauthorized

 

MFA Reset

  • If MFA is resent, an email alert informs user MFA has been reset

  • This reset requires reconfiguration

Account Locked

  • If the account is locked, an email alert notifies user of lockout due to failed attempts

  • This alert provides recovery option

Best Practices & Implementation Notes

  • Enforce MFA at the company or agency level for consistent security coverage

  • Ensure users securely store recovery codes during setup

  • Use MFA reset cautiously, as it requires full reconfiguration by the user

  • Communicate enforcement changes clearly to avoid login disruptions

For additional guidance on tailoring your approach, consult your Keen account manager.