Tenant Members MFA: What is considered "Pro MFA"?

For better security, all of our Tenant members have now activated TOTP (One-time) MFA and use 1Password for the one-time code.

However, we received a notification saying “Pro MFA has exceeded your plan limit for this month” and “Users that completed MFA using DUO or OTP apps like Google Authenticator, counted per calendar month, per tenant.”.

The wording for “Users that completed MFA using DUO or OTP apps like Google Authenticator” seems a little ambiguous: are tenant members that use any TOTP (one time code) considered a Pro MFA method?

In the quota report it states that 1 user is using Google Auhtenticator.

Hey there @sev welcome to the community!

Pro MFA includes any 3rd party TOTP app - Google Authenticator, DUO, etc.

Hope this helps to clear things up!

Thanks @tyf. Can you clarify out of the below Tenant MFA options what is considered “Pro MFA”?

There’s nowhere in the UI that I can see it mentioning what is “Pro MFA” and what isn’t.

Hey there @sev happy to help!

You should be able to see the “Pro” and “Enterprise” tags for each factor if you navigate to Security → Multi-factor Auth in your dashboard.

Hope this helps!

@tyf could you explain why all types of Multi-factor Auth are considered “Pro” features even though it is a common security practise to offer MFA these days?

Also, do both Auth0 admin/tenant and regular user accounts count towards the same limit?

@tyf We’re turning off MFA methods for tenant members as we’re not 100% sure whether the screengrab you disclosed also directly correlates with MFA options for tenant members.

It might be easier if you could disclose a bulleted list of all MFA methods for tenant members that highlight which methods are not Pro/Enterprise and which are Pro/Enterprise.

Hey @sev and @jonathanm!

Sorry for the confusion here - Pro/Enterprise MFA relate to end user usage and not tenant members. Tenant member MFA is a treated separately.

@jonathanm If this in regards to end users, MFA does require significant lifting on the Auth0 side and thus requires a subscription.

Thanks @tyf. I couldn’t see anything in the latest link you shared which mentions Pro/Enterprise MFA for tenant members.

Sorry for the confusion here - Pro/Enterprise MFA relate to end user usage and not tenant members. Tenant member MFA is a treated separately.

To clarify: are any of the tenant MFA options classed as Pro/Enterprise MFA? And if so, can you please simply give us a bulleted list of the tenant member options which are Pro/Enterprise MFA.

Hey @sev, happy to help where I can!

Both Pro and Enterprise MFA apply only to your users (end users). There are no MFA restrictions on dashboard admins setting MFA for their Auth0 user profiles.

Does that help to clarify?

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.