Dear Team,
We would like to request guidance on using IBM Verify Identity Access (ISVA) as an MFA solution without federation.
Currently, we are always using federation (SAML or OIDC) with enforced MFA. However, our new requirement is to use ISVA only as MFA, and the environment is not accessible through the internet.
We are considering using Protected Applications and Access Policies to apply MFA. The challenge is how to obtain the user ID from the login session in order to identify the user and enforce MFA, without prompting for the user ID and password again.
Since this environment has no internet access, we cannot use mobile push notifications. Our plan is to rely on email and SMS as the MFA factors.
Could you please advise on the best approach to achieve this requirement?
Thanks & Best Regards,
------------------------------
Mohamed Ahmed
------------------------------