You can set the number of days for which the users can postpone the enabling of second factor for authentication.
-
You are assigned the Manage Tenant Configuration role. For more information about how to assign administrator roles, see Edit Administrator Authorizations.
-
You have configured the application or the tenant to require two-factor authentication. For more information, see Configure Risk-Based Authentication for an Application or Configure Default Risk-Based Authentication for All Applications in the Tenant.
The number of days for which users can postpone the enabling of second factor can be set between 1 and 14 days. The configuration is valid for all applications in the tenant.
If the tenant or application requires two-factor authentication, and the users don't have an enabled two-factor authentication method, or the method that is enabled is not among the ones required by the application, at sign-in users can choose to skip the enabling of two-factor authentication for the period defined by the tenant administrator. The users can sign in without providing a second factor until the grace period expires.
Users can be notified for their choice, if the security alert notification is switched on. They receive a security alert email after they first skip the enabling of two-factor. For more information about how to configure the e-mail alerts, see Send Security Alert Emails.
-
Sign in to the administration console for SAP Cloud Identity Services.
-
Under Applications and Resources, choose the Tenant Settings tile.
At the top of the page, you can view the administrative and license relevant information of the tenant.
-
Choose the Multi-Factor Authentication list item.
-
Under Additional Settings for Multi-Factor Authentication, choose Edit.
-
Under Second Factor Activation Postponement, choose Enabled.
-
Manually configure the number of days for which users can postpone the enabling of second factor.
-
Save your changes.
If the operation is successful, the system displays the message Additional Multi-Factor Authentication Settings updated.
Related Information
Deactivate Two-Factor Authentication
Deactivate User Devices for TOTP Two-Factor Authentication
Remove User Device for Web Two-Factor Authentication
Allow Users to Protect Accounts with Second Factor for Authentication