Step-up Authentication
Requiring additional authentication when a user attempts a higher-risk action, such as changing email or initiating a large payment. Implemented via OIDC acr_values and amr claims in modern stacks.
Step-up is how you keep everyday access frictionless without leaving sensitive operations protected only by a session from three days ago. Implement it as a property of the action rather than of the login: changing a recovery email, adding a payee, or exporting data should each declare the assurance they require, and the application should ask for it at that moment.
See also: adaptive auth, risk-based auth, MFA, SCA
Related on Start with Identity
- GlossaryConditional Access
Policy-driven access decisions evaluated at sign-in time. Inputs include identity, device, location, risk signals, and application sensitivity. Microsoft Entra
- GlossaryPhishing-Resistant MFA
Multi-factor methods that cannot be relayed or replayed by a phishing site, principally FIDO2 security keys and passkeys. Recommended by NIST and CISA over OTP
- GlossaryAuthenticator Assurance Level (AAL)
NIST 800-63B levels describing authentication strength. AAL1: single factor. AAL2: multi-factor. AAL3: multi-factor with phishing-resistant cryptographic authen
- BlogEntra ID stops delivering SMS and voice codes on February 1, and global admins go last
From February 1, 2027, Microsoft stops providing SMS and voice authentication in Entra ID, and users with no other method must register a passkey to keep signin
- CVEOkta Verify for Windows local privilege escalation
Okta Verify on Windows could be turned into a local privilege escalation. The MFA app on the endpoint is part of the identity plane. Pair with Okta's 2024 FastP
- BlogThe SMS off-ramp has a date now: what Entra, GOV.UK and America.gov mean for your MFA plan
Microsoft stops delivering SMS and voice codes in Entra ID on February 1, 2027. The UK has put passkeys in front of 23 million citizens, and the new federal fro