Using Single Sign-On (SSO) with Multi-Factor Authentication
This guide explains the three ways you may be asked to sign in and complete multi-factor authentication (MFA), depending on how your organization has set up identity and access management.
Overview
Multi-factor authentication (MFA) adds a second layer of verification beyond your username and password, so an account cannot be accessed with a password alone. How MFA works for you depends on whether your organization uses its own identity provider (IDP) for single sign-on (SSO), and whether that IDP already enforces MFA.
There are three possible sign-in experiences. Use the table below to identify which one applies to you, then jump to the matching section for step-by-step instructions.
|
Scenario |
Does your organization have its own IDP? |
Does that IDP provide MFA? |
What you need to do |
|
1 |
Yes |
Yes |
Nothing — log in through your organization as usual. |
|
2 |
Yes |
No |
An administrator enrolls in Konexus MFA and verifies their email address. |
|
3 |
No (uses Konexus MFA directly) |
No |
Enroll in Konexus MFA and choose email or an authenticator app. |
Scenario 1: Your Organization's IDP Already Provides MFA
Who this is for: Organizations that have connected their own identity provider (e.g., Okta, Azure AD/Entra ID, Ping, Google Workspace) and that IDP already enforces MFA for its users.
If your organization's IDP already requires MFA before granting access, no additional MFA setup is needed inside Konexus. Your existing MFA method (authenticator app, push notification, security key, etc.) continues to be used exactly as it is today.
Steps
- Go to the Konexus login page (https://apps.alertsense.com) and enter your email address associated with your organization

- You will be redirected to your organization's identity provider sign-in page.

- Complete your organization's existing MFA challenge (authenticator app code, push approval, security key, etc.) exactly as you would for any other application.

- Once verified, you are redirected back and signed in to Konexus. No further enrollment is required.

Note: Because MFA is enforced by your organization's IDP, any changes to MFA methods (adding a device, resetting an authenticator, etc.) must be made through your organization's identity provider or IT help desk, not within Konexus.
Scenario 2: Your Organization's IDP Does Not Provide MFA
Who this is for: Organizations that have connected their own identity provider for single sign-on, but that IDP does not enforce MFA. In this case, Konexus requires the account's email address to be verified before logging in.
Because your organization's IDP does not provide MFA, Konexus requires an administrator to verify their email address before access is granted. This ensures every account is protected by MFA even when the connected IDP does not enforce it.
Steps
- Go to the Konexus login page (https://apps.alertsense.com) and enter your email address associated with your organization.

- Because your IDP does not enforce MFA, Konexus detects this and will require you to verify your email address.

- the verification code sent to your email address.Konexus sends a verification code to your email address. Enter the verification code sent to your email address.

- Once verified, you are redirected back and signed in to Konexus.
Scenario 3: Your Organization Uses Konexus MFA Directly
Who this is for: Organizations that do not connect an external identity provider and instead rely on Konexus's built-in MFA to secure sign-in.
If your organization does not use an external IDP, you will sign in directly with your Konexus username and password, and enrollment in Konexus MFA is required. During enrollment you choose to receive your verification code either by email or through an authenticator app.
Steps
- Go to the Konexus login page (https://apps.alertsense.com) and enter your email address associated with your organization.

- If you have not yet enrolled, you will be prompted to set up MFA before you can continue.
- Choose your preferred MFA method: “Email” to receive a one-time code at your email on file, or “Authenticator App” to scan a QR code with an app such as Google Authenticator or Microsoft Authenticator.
- If you selected Email, enter the one-time code sent to your inbox. If you selected Authenticator App, scan the QR code and enter the 6-digit code generated by the app.
- Submit the code to complete enrollment. Your MFA method is now saved to your account.
- On every future login, enter your username and password, then enter the MFA code from your chosen method (email or authenticator app) to access Konexus.
You can change your MFA method (switch between email and authenticator app) at any time from your account security settings.
Need Help?
If you are unsure which scenario applies to your organization, or you run into an issue while logging in or enrolling in MFA, contact your Konexus administrator or Konexus Support for assistance. You can also refer to this article for more information about MFA.