Skip to main content

Does Riot support multi-factor authentication (MFA)?

This question comes up regularly, particularly in security questionnaires. Here is the factual answer.

1️⃣ Signing in with SSO

The vast majority of our customers sign in to Riot through their corporate identity provider — Google, Microsoft, Slack or Okta.

In that case, authentication is handled entirely by your identity provider. This means your multi-factor authentication policy applies to Riot, just as it does to any other application in your estate: if your provider enforces a second factor, signing in to Riot benefits from it automatically. The same goes for your conditional access rules, your session policies and your device compliance requirements.

👍 Our recommendation: this is the setup to favour if you have security or compliance requirements. You keep control of your authentication policies in the same place as for your other tools, without having to redefine them in Riot.

👉 For the setup, see the SSO configuration articles: Entra, OneLogin, Okta and JumpCloud.

2️⃣ Signing in with a magic link

Riot also offers a passwordless magic link sign-in. It relies on the combination of two things sent by email: a single-use link and a 6-digit code shown only to the person who made the request. Opening the link is therefore not enough to sign in.

3️⃣ What to note for a compliance file

Riot does not include a multi-factor authentication mechanism of its own on its sign-in form. Multi-factor authentication is obtained by connecting Riot to your identity provider, which remains the source of truth for your access policies.

Key takeaways

  • With SSO, your multi-factor authentication policy applies to Riot.

  • Supported providers: Google, Microsoft, Slack, Okta, along with OIDC and SCIM configurations for enterprise deployments.

  • The magic link pairs a single-use link with a 6-digit code.

Did this answer your question?