MFAPortal

Multi-factor authentication for teams that do not have a security department.

MFA Portal adds a second step to your existing Google Workspace or Microsoft 365 sign-ins. Your directory stays where it is; we handle enrolment, policies, recovery and the audit record.

Deployed by clinics, school districts, law firms and manufacturers between 25 and 2,000 staff.

Console summary
directory: Microsoft Entra ID
synced_groups: 14
users_enrolled: 412 / 431
methods: totp, push, webauthn
policy: admins require webauthn
events_24h: 2,908
failed_24h: 63

What it does

A second step on every sign-in

TOTP codes, number-matched push to the mobile app, or WebAuthn security keys — chosen per group and per application. Users who lose a device use self-service recovery instead of calling you.

Your directory stays yours

Read-only sync from Microsoft Entra ID, Google Workspace or any LDAP v3 directory. We never receive password hashes and we never store them: your password check stays with your identity provider.

Recovery that leaves a trail

Self-service recovery with a 10-minute delay and a next-day notice to the account owner. An administrator can override, but has to record a reason, and the override is in the audit log.

Under the hood

AreaDetail
Authentication methodstotp (RFC 6238), push with number matching, webauthn (FIDO2), sms fallback (opt-in)
Directory syncSCIM 2.0, Microsoft Graph, Google Workspace Admin SDK, LDAP v3 over TLS
Policy engineper group, per application, per sign-in risk; session lifetime 1h to 12h
AdministrationSAML 2.0 SSO, WebAuthn required for admin roles, role-based scopes
AuditJSON and syslog export, 400 days retention, per-event user agent and IP
Regionseu-central-1 (Frankfurt) or us-east-1 (Virginia), chosen at setup

Integration details, the REST API reference and the SCIM schema are sent with a trial account.

A typical rollout

  1. Connect the directory

    A read-only service account is created in your tenancy and the groups you want to protect are imported. Fifteen minutes with your IT contact, and no change to how users sign in yet.

  2. Decide who needs what

    Start with administrators, finance and anyone with access to personal data. Those groups get security keys or push; everyone else gets TOTP with SMS only as an explicit opt-in.

  3. Invite by group

    Invitations are sent in batches with a seven-day link, so a rollout is measured rather than announced. The console shows who has enrolled, who has not, and who is stuck, and you can pause a batch at any point.

  4. Watch the first two weeks

    Failed attempts, recovery events and unenrolled accounts appear on one page. Most rollouts settle after the second batch; we contact you if the numbers do not.

Operations

99.97%
availability, trailing 12 months.

Annual
independent penetration test.

Regional
data stays in the region you choose.

SOC 2 Type II
report available under NDA.