Updating an MFA policy
Note
This feature is at the Preview stage.
To update an MFA policy:
-
Log in to Yandex Identity Hub
. -
In the left-hand panel, select
Security settings. -
Go to the MFA policies tab.
-
In the MFA policy list, click
in the policy row and select Edit. In the window that opens:-
In the Name field, enter a new name for the policy. Follow these naming requirements:
- It must be from 1 to 63 characters long.
- It may contain lowercase Latin letters, numbers, and hyphens.
- It must start with a letter and cannot end with a hyphen.
-
Optionally, enter a policy description in the Description field.
-
If required, use Policy active to activate or deactivate the policy.
-
In the Factor types field, select additional authentication factors required for users from the policy's target groups to verify their identity:
-
Any. This option allows users to select one of the following additional authentication factor standards:-
WebAuthn
(FIDO2 ). The acceptable additional authentication factors may include hardware keys such as Rutoken or YubiKey , Passkeys authenticators, platform authenticators such as Windows Hello , etc.Warning
Browser extensions with password input control may cause errors when entering additional factors. We recommend disabling such extensions in case of errors.
-
TOTP
. This standard enables using one-time codes generated by dedicated authenticator apps as an additional authentication factor.
-
-
Phishing-resistant. This option enforces the WebAuthn authentication factors as the most secure ones.
-
-
In the Creation deadline field, specify the period in days during which the user must add a second authentication factor after registration.
-
In the Lifetime field, set the credential validity period, in days.
Upon expiry of the specified timeout, the user will need to authenticate with the additional factor again.
-
Click Save.
-
Note