Skip to main content

Password & MFA

Password sign-in​

Standard email/password (or any registered identifier + password) sign-in. Password policy — minimum length, character-class requirements, breach-list checking — is configured on the Password connector's own settings page, like any other connector: Console → Sign-in Methods → Email & Password → Configure (tenant-wide) or a specific app's own Connectors → Configure for a per-app override. See Apps & Connectors for how the Floor/Override model applies to connector settings fields, and Credential Health for password age tracking and breach-check.

Multi-factor authentication​

Once enabled for a tenant, MFA can be required at sign-in via:

  • TOTP — any standard authenticator app (Google Authenticator, Authy, 1Password, etc.).
  • Magic Link as a step-up factor — a "click the link we emailed you" second factor, distinct from Magic Link as a primary sign-in method (see Magic Link).
  • Recovery codes — one-time backup codes generated at MFA setup, for when a user loses their authenticator device. LoginLink proactively warns a user in their account settings when their remaining recovery codes run low.

Trusted devices​

A user can mark a device as trusted after completing MFA once, skipping the second factor on that device for a configurable period. Trusted devices are visible and individually revocable from the user's own account settings and from Console for a tenant admin.

Recovery flow​

If a user loses access to their MFA method entirely, a self-service recovery flow (email-based, with a deliberate delay and clear audit trail) lets them regain access without a support ticket — configurable per tenant, since some organizations prefer to require admin-assisted recovery instead.

Configuring MFA for your tenant​

MFA configuration is split across a few dedicated Console pages rather than one settings screen — see MFA & Recovery for the full walkthrough:

  • Which second factor applies to which sign-in method — Console → MFA & Recovery → Method Rules, narrowed from whatever the platform allows.
  • Auto-send behavior — Console → MFA Settings.
  • Recovery mode, exhaustion policy, and low-codes warnings — Console → MFA Recovery, in three independently-saved sections.
  • Trusted-device duration — Console → Session Settings (see Session & Token Policy).

A platform-level ceiling can force MFA on, or restrict which recovery modes are even selectable, regardless of a tenant's own preference — ask your LoginLink platform operator if you're on a self-hosted instance and this applies to you.