Using Single Sign-On (SSO) with Multi-Factor Authentication
This guide explains the three ways you may be asked to sign in and complete multi-factor authentication (MFA), depending on how your organization has set up identity and access management.
Overview
Multi-factor authentication (MFA) adds a second layer of verification beyond your username and password, so an account cannot be accessed with a password alone. How MFA works for you depends on whether your organization uses its own identity provider (IDP) for single sign-on (SSO), and whether that IDP already enforces MFA.
There are three possible sign-in experiences. Use the table below to identify which one applies to you, then jump to the matching section for step-by-step instructions.
|
Scenario |
Does your organization have its own IDP? |
Does that IDP provide MFA? |
What you need to do |
|
1 |
Yes |
Yes |
Nothing — log in through your organization as usual. |
|
2 |
Yes |
No |
An administrator is required to verify access to their email address with each log in. |
|
3 |
No (uses Konexus Account directly |
No |
Enroll in MFA for Konexus Account by choosing email or an authenticator app. |
Scenario 1: Your Organization's IDP Already Provides MFA
Who this is for: Organizations that have connected their own identity provider (e.g., Okta, Azure AD/Entra ID, Ping, Google Workspace) and that IDP already enforces MFA for its users.
If your organization's IDP already requires MFA before granting access, no additional MFA setup is needed inside Konexus. Your existing MFA method (authenticator app, push notification, security key, etc.) continues to be used exactly as it is today.
Steps
- Go to the Konexus login page (https://apps.alertsense.com) and enter your email address associated with your organization

- You will be redirected to your organization's identity provider sign-in page.

- Complete your organization's existing MFA challenge (authenticator app code, push approval, security key, etc.) exactly as you would for any other application.

- Once verified, you are redirected back and signed in to Konexus. No further enrollment is required.

Note: Because MFA is enforced by your organization's IDP, any changes to MFA methods (adding a device, resetting an authenticator, etc.) must be made through your organization's identity provider or IT help desk, not within Konexus.
Scenario 2: Your Organization's IDP Does Not Provide MFA
Who this is for: Organizations that have connected their own identity provider for single sign-on, but that IDP does not enforce MFA. In this case, Konexus requires the account's email address to be verified before logging in.
Because your organization's IDP does not provide MFA, Konexus requires an administrator to verify access to their email address before log in is granted. This ensures every account is protected by MFA even when the connected IDP does not enforce it.
Steps
- Go to the Konexus login page (https://apps.alertsense.com) and enter your email address associated with your organization.

- Because your IDP does not enforce MFA, Konexus detects this and will require you to verify access to your email address by sending a code to your email address.

- Enter the verification code sent to your email address.

- Once verified, you are redirected back and signed in to Konexus.
Scenario 3: Your Organization Uses a Konexus Account
Who this is for: Organizations that do not connect an external identity provider and instead rely on Konexus's built-in MFA to secure sign-in.
If your organization does not use an external IDP, you will sign in directly with your Konexus username and password, and enrollment with your Konexus Account in MFA is required. During enrollment you choose to receive your verification code either by email or through an authenticator app.
Steps
- Go to the Konexus login page (https://apps.alertsense.com) and enter your email address associated with your organization.

- If you have not yet enrolled, you will be prompted to set up MFA before you can continue.

- Choose your preferred MFA method: “Email” to receive a one-time code at your email on file, or “Authenticator App” to scan a QR code with an app such as Google Authenticator or Microsoft Authenticator.


- If you selected Email, enter the one-time code sent to your inbox. If you selected Authenticator App, scan the QR code and enter the 6-digit code generated by the app.


- Submit the code to complete enrollment. Your MFA method is now saved to your account along with provided Recovery Codes if using an Authenticator App.

- On every future login, enter your username and password, then enter the MFA code from your chosen method (email or authenticator app) to access Konexus.
You can change your MFA method (switch between email and authenticator app) at any time from your account security settings.
Need Help?
If you are unsure which scenario applies to your organization, or you run into an issue while logging in or enrolling in MFA, contact your Konexus administrator or Konexus Support for assistance. You can also refer to this article for more information about MFA.