# Multifactor Authentication

**URL:** <https://community.triggre.com/t/multifactor-authentication/328>\
**Category:** Feature requests\
**Created:** [May 12, 2023, 9:04am UTC](https://community.triggre.com/t/multifactor-authentication/328 "2023-05-12T09:04:18Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![roland.huijser](https://avatars.discourse-cdn.com/v4/letter/r/5f9b8f/32.png) [@roland.huijser](https://community.triggre.com/u/roland.huijser)\
**Post date:** [May 12, 2023, 9:04am UTC](https://community.triggre.com/t/multifactor-authentication/328/1 "2023-05-12T09:04:18Z")

</div>

Is it possible to use Multifactor Authentication in Triggre.

---

<div class="post-metadata">

**Author:** ![sylvester](https://yyz1.discourse-cdn.com/flex035/user_avatar/community.triggre.com/sylvester/32/787_2.png) [@sylvester](https://community.triggre.com/u/sylvester)\
**Post date:** [May 13, 2023, 11:11am UTC](https://community.triggre.com/t/multifactor-authentication/328/2 "2023-05-13T11:11:27Z")

</div>

Hi Roland,  
The native login procedure of Triggre does not support that yet, though I believe it is on their roadmap (@Jesse am I correct?).  
It should be possible to implement SSO with a connection to AAD, then the Microsoft MFA will take care of this. I have never implemented this yet myself, but I do know you will need the people of Triggre to help you with it.  
Also, I have built an MFA-like process for a client, that works well in practice and provides a similar level of security. This requires some explanation, so let me know if you are interested and I’ll be happy to share it with you.

---

<div class="post-metadata">

**Author:** ![roland.huijser](https://avatars.discourse-cdn.com/v4/letter/r/5f9b8f/32.png) [@roland.huijser](https://community.triggre.com/u/roland.huijser)\
**Post date:** [May 15, 2023, 7:13am UTC](https://community.triggre.com/t/multifactor-authentication/328/3 "2023-05-15T07:13:43Z")

</div>

I am interested, please send me some screenprints.

---

<div class="post-metadata">

**Author:** ![Jesse](https://yyz1.discourse-cdn.com/flex035/user_avatar/community.triggre.com/jesse/32/88_2.png) [@Jesse](https://community.triggre.com/u/Jesse)\
**Post date:** [May 15, 2023, 9:27am UTC](https://community.triggre.com/t/multifactor-authentication/328/4 "2023-05-15T09:27:40Z")

</div>

Hi @roland.huijser and @sylvester,

Indeed, natively we do not yet support two-factor-authentication, other than through Microsoft’s Active Directory Federation Services (ADFS), which is available in the Enterprise plan.

However, as @sylvester said, you can build something yourself that will do the trick. Here’s a plan on how to do it, taking into account recently released functionality such as the _random number_ function:

**Setting up**

1. Create an extra role in your published application, e.g. _Authenticated_. This role will need to have access to all the functionality you want authenticated users to have access to.
2. Have the default role only be permitted to access the _Start_ user flow (see below).
3. Add a date/time property to the _User_, called _Last authenticated_
4. Add a text property to the _User_, called _Authentication code_

![image](https://canada1.discourse-cdn.com/flex035/uploads/triggre/original/1X/d0629f86b5fa3912e339551ed72660db4e9ada26.png)

**Flow part - Authenticate user with 2FA**

1. If the user’s _Last authenticated_ is less than or equal to X hours ago, they are authenticated. As output of the flow part, _Authenticated_ should be _True_.
2. Also, make sure to set the user’s _Last authenticated_ to the current date and time.
3. If the user’s _Last authenticated_ is over X hours ago, the result is _False_.

 ![image](https://canada1.discourse-cdn.com/flex035/uploads/triggre/original/1X/c5d41f9eb1a0cc6285fd0d43fef52867835bbb8b.png)

**Flow part - Generate 2FA code**

1. Create a code, the easiest way is to use 1 calculation: MAKE ( RANDOM NR BETWEEN 100000 AND 999999 ) A TEXT. This gives you a 6 digit authentication code.
2. Store this number as the code for the user.
3. Send the code to the user by email (or SMS, using the Web API and Twilio for example)

 ![image](https://canada1.discourse-cdn.com/flex035/uploads/triggre/original/1X/820a7734d20a221fe6a751e8a4d1e060523c5a8a.png)

**User flow - Start**  
Make a user flow that will always be the first user flow to be opened (place it in the first section, and first category of the appearance):

1. Start with the _Authenticate user with 2FA_ flow part
2. If the user is authenticated, simply direct them to a start page, e.g. a dashboard page.
3. If the user is not authenticated, remove the _Authenticated_ role from them, generate a 2FA code for them and direct them to a page where they can fill in their code.
4. After submitting the code, check the submitted code against the one in their profile.
5. If the code is incorrect, show an _Authentication failed_ page, with only the option to _Retry_.
6. If authentication is successful, assign the _Authenticated_ role, and then direct them to a _Authentication successful_ page. This extra step is important, because assigning the role happens in the background. This means the entire menu will not yet show up on this first page.
7. From the success page, have 1 option, called _Next_. this leads to the regular start page.

 ![image](https://canada1.discourse-cdn.com/flex035/uploads/triggre/original/1X/105a4962af4c1b0f475a5c98fe455a920197f6bf.png)

**Further enhancements**  
You can make an automation flow that runs in the background every hour or couple of hours, to check users. This automation flow can then empty the last authenticated date for those users that are no longer authenticated. For performance, add a date/time property _Automated log off_. Set this date.

A second automation flow, with a data triggre, can then fire upon changing the _Automated log off_ value. It should remove the _Authenticated_ role. This will make sure that the application behaves a little bit nicer for people who have been logged out for a while and then log back in (the menu will not be visible for them, in this case).

_Disclaimer_  
I quickly made this functionality off the top of my head without detailed testing, just to provide this example. I think I got it completely right, but then again, maybe I forgot a small thing. If that’s the case please let me know here, and I’ll update this post 🙂

Hope this is clear enough and works in your case!

---

<div class="post-metadata">

**Author:** ![roland.huijser](https://avatars.discourse-cdn.com/v4/letter/r/5f9b8f/32.png) [@roland.huijser](https://community.triggre.com/u/roland.huijser)\
**Post date:** [May 16, 2023, 8:21am UTC](https://community.triggre.com/t/multifactor-authentication/328/5 "2023-05-16T08:21:46Z")

</div>

Is it perhaps a suggestion to make this a Triggre template.

---

<div class="post-metadata">

**Author:** ![sylvester](https://yyz1.discourse-cdn.com/flex035/user_avatar/community.triggre.com/sylvester/32/787_2.png) [@sylvester](https://community.triggre.com/u/sylvester)\
**Post date:** [May 23, 2023, 7:03pm UTC](https://community.triggre.com/t/multifactor-authentication/328/6 "2023-05-23T19:03:05Z")

</div>

Hi @Jesse and @roland.huijser,  
I’ve built it almost exactly like that, however I added a TTL (Time to live) value to the application settings, combined with a ‘Validated’ true/false and a ‘Valid until’ date/time in the user. When logging in, the procedure checks whether the user has already validated and if code is still valid, based on the ‘Validated’ and ‘Valid until’ value in the user. If still valid, the procedure will continue to the landing page, if not or if not validated, the authentication screen shows and a new code will be sent to the user.  
The TTL can be set by a duration field in the Application settings.  
It’s a bit of a different approach, but basically it is the same process.
