I am planning to implement B2C scenario for MFA, the following are my questions

  1. Can I allow a user to configure multiple MFA? i.e. user can setup SMS, email as well as Google authenticator TOTP.
  2. Can I combine MFA? for example, a user receives same OTP on the cell phone as well as on email?


  1. Yes it’s doable. Ref:

  2. I’m pretty sure you can as we have an MFA API and I believe you will just need to trigger both of the flows and put in one of the codes. More on that here:

