Configurable factors
Choose which factors are available and which are acceptable for a given application or population, rather than accepting a fixed list.
Risk-based multi-factor authentication with configurable factors, policies and network zones — stronger when the situation warrants it, invisible when it does not.
Applying the same authentication challenge to every sign-in either frustrates people or under-protects the risky cases. Adaptive MFA evaluates each attempt against the policy you define — the network zone it comes from, the behaviour pattern, the sensitivity of the application — and steps the challenge up only where it is warranted.
The mechanics behind the capability — what the platform does, and where it does it.
Choose which factors are available and which are acceptable for a given application or population, rather than accepting a fixed list.
Define trusted and untrusted ranges so that location becomes an input to the decision instead of an afterthought.
Compare an attempt against the established pattern for that identity and treat the unusual ones differently.
Authentication rules are expressed declaratively, so the policy that governs a login can be reviewed without reading code.
Who feels the difference once Adaptive MFA is in place, and how.
End users
Routine sign-ins from known conditions stay quick; the unusual ones get challenged, which is where the protection is actually needed.
Security
A stolen password on its own stops being enough to get in, which removes the payoff from most phishing.
Application owners
Sensitive applications can demand more without imposing that standard on everything else.
Audit
Every challenge and outcome is recorded, so you can demonstrate the control operated rather than assert that it exists.
It works because the other capabilities share the same identity fabric. The quickest way to judge that is to watch it run against your own use cases.