Zetect

Multi-factor that reacts to risk

Risk-based multi-factor authentication with configurable factors, policies and network zones — stronger when the situation warrants it, invisible when it does not.

Applying the same authentication challenge to every sign-in either frustrates people or under-protects the risky cases. Adaptive MFA evaluates each attempt against the policy you define — the network zone it comes from, the behaviour pattern, the sensitivity of the application — and steps the challenge up only where it is warranted.

How Adaptive MFA works

The mechanics behind the capability — what the platform does, and where it does it.

Sign-in attemptuser and applicationRisk evaluatedrules and signalsDecisionallow, step up, denyOutcome recordedon the audit trailSIGNALS THE POLICY CAN USENetwork zone — whether the request comes from a trusted rangeBehaviour detection — how this attempt compares with the established patternApplication sensitivity — the factors that application requires

Configurable factors

Choose which factors are available and which are acceptable for a given application or population, rather than accepting a fixed list.

Network zones

Define trusted and untrusted ranges so that location becomes an input to the decision instead of an afterthought.

Behaviour detection

Compare an attempt against the established pattern for that identity and treat the unusual ones differently.

Rules you can read

Authentication rules are expressed declaratively, so the policy that governs a login can be reviewed without reading code.

What it changes

Who feels the difference once Adaptive MFA is in place, and how.

End users

Friction where it belongs

Routine sign-ins from known conditions stay quick; the unusual ones get challenged, which is where the protection is actually needed.

Security

Credential theft loses value

A stolen password on its own stops being enough to get in, which removes the payoff from most phishing.

Application owners

Policy that adapts per system

Sensitive applications can demand more without imposing that standard on everything else.

Audit

Evidence of enforcement

Every challenge and outcome is recorded, so you can demonstrate the control operated rather than assert that it exists.

See Adaptive MFA in context

It works because the other capabilities share the same identity fabric. The quickest way to judge that is to watch it run against your own use cases.