IAM
Multi-Factor Authentication
CoreLink supports multiple MFA factor types per user: TOTP (Google Authenticator, 1Password, Authy), WebAuthn/passkeys for phishing-resistant hardware and platform authenticators, backup codes for recovery, and Email or SMS OTP as fallback factors. Users can register multiple factors and choose which to present at login.
Tenant administrators configure MFA enforcement policy -- required for all users, required for privileged roles only, or required at step-up checkpoints (accessing production secrets, approving JIT access, administering tenants). Policies integrate with the session broker so step-up challenges gate access to high-sensitivity session targets.
Key Configuration
- Allowed factor types (TOTP, WebAuthn, Email OTP, SMS OTP)
- Enforcement policy (always, privileged-only, step-up checkpoints)
- Backup code generation policy
- Session re-verification interval