Support Multi-Factor Authentication (MFA) for Admin Users Accessing Eptura Engage via Local Login
Customers using SSO authentication can still access Eptura Engage through the direct local login page. While this alternative authentication path may be required for operational reasons, it creates a potential security concern as SSO controls are bypassed when local credentials are used.
Requested Enhancement
Provide the ability to enforce Multi-Factor Authentication (MFA) for users authenticating through the standard Eptura Engage login page, particularly for administrative accounts.
Possible configuration options:
- Enable MFA for all local login users.
- Enable MFA specifically for users with administrative privileges.
- Allow tenant-level configuration of MFA enforcement policies.
Business Value
Reduces security risk associated with local authentication endpoints.
Provides an additional security layer for privileged/admin accounts.
Helps customers satisfy internal security and compliance requirements.
Offers a practical mitigation where removal of the local login mechanism is not feasible.
Use Case
It was identified that users can authenticate through the direct login page instead of SSO. Since the local login path must remain available, enforcing MFA for administrator accounts would significantly reduce the associated security risk and may address internal security incident findings.
Priority / Impact
Medium to High
Customer Benefit
Improved security posture for organizations using SSO while maintaining necessary fallback/local authentication capabilities.