Security - Adaptive MFA

The Most MFA Options in Higher Ed. One Method Per Person.


A campus is not an office. Testing centers ban phones, some students don't carry one, and a professor emeritus signs in differently than a sysadmin. QuickLaunch Adaptive MFA matches the method to the person and the friction to the risk passkeys to security questions, geofenced step-up to phoneless paths enforced from the moment an account is claimed.

See It to Believe It

9 method families · per-role deployment · enforced at account activation

Adaptive MFA institutions across higher education
Why Adaptive

One-Size-Fits-All MFA Fits a Campus Worst of All.

Force everyone onto phone push and you lock out the testing center, the phoneless student, and the shared lab machine on day one. Adaptive MFA reads the context who is signing in, from where, at what risk and applies exactly the verification the moment calls for. Security goes up because friction lands only where it belongs.

1

Context-aware verification

routine sign-ins from known devices stay fast; unusual location or geofence exits trigger step-up.

2

Role-based rules

students, faculty, staff, and privileged admins each carry their own method requirements and risk baselines.

3

Phoneless paths built in

email OTP, security questions, hardware tokens, and passkeys cover testing centers and phone-free students.

4

Phishing-resistant at the top

passkeys and hardware tokens to NIST AAL2 for the accounts that matter most.

5

Enforced at activation

method enrollment happens during account claim, so there is never an unprotected gap and never an enrollment campaign.

6

Every factor visible

MFA factors in use, failed attempts, and brute-force patterns feed the reporting layer in real time.

See It

Watch: Claimed in Under Two Minutes

From welcome notification to a protected, ready-to-use account the whole claim, in real time.

The Methods

Every Way to Verify, One Platform

Deploy different methods to different groups by risk profile the strongest factor a person can use becomes the factor they do use.

Passkeys

Phishing-resistant, 8× faster sign-in, device biometrics as the key.

Biometrics

Face and fingerprint verification on the user's own device.

Hardware Tokens

YubiKeys and FIDO keys for admins and privileged access.

Mobile Push

One-tap approval through the mobile authenticator.

Authenticator Apps

Time-based codes from any standard authenticator.

Email OTP

One-time passcodes by email — the phoneless path that always works.

SMS OTP

Text-message codes where policy allows them.

Geofencing Step-Up

Location-aware rules that add verification when sign-ins leave the expected zone.

Adaptive Rules

Friction Where the Risk Is. Nowhere Else.

Adaptive MFA evaluates every sign-in in context. The same student gets a frictionless morning login from the dorm and a step-up challenge when their credentials show up from another continent automatically, by rule, with every decision logged.

  • Known device, expected location: sign in and go no unnecessary prompt.
  • New device or unusual location: step-up verification before access.
  • Privileged role: phishing-resistant factor required, every time.
  • Testing center: phoneless method honored the exam starts on time.
Results Across the Network

The Numbers Institutions See

9
MFA method families the most in higher ed
75,000
users rolled out to MFA at a single campus
AAL2
NIST phishing-resistance with passkeys & tokens
Day 1
MFA enrolled at account activation
200+
institutions on QuickLaunch
FAQ

Frequently Asked Questions

What is QuickLaunch Adaptive MFA?
Adaptive MFA verifies identity with a second factor that adjusts to context. Instead of one-size-fits-all prompts, it evaluates who is signing in, from where, and at what risk then applies the right level of friction. Low-risk sign-ins stay fast; unusual ones get stepped up. It ships with the widest range of MFA methods in higher education, so every person on campus has a method that works for their situation.
What MFA methods does QuickLaunch support?
Passkeys, biometrics, hardware tokens like YubiKeys, mobile push notifications, authenticator apps, email one-time passcodes, SMS one-time passcodes, security questions, and geofencing-based step-up. Different methods can be deployed to different user groups by risk profile passkeys for those who can, email OTP for phoneless students, hardware tokens for privileged admins.
What about students who don't have a phone?
Campus is not an office, and phone-only MFA breaks in campus reality: testing centers ban phones, some students don't carry smartphones, and shared devices are everywhere. QuickLaunch provides phoneless paths email OTP, security questions, hardware tokens, and passkeys on shared or personal devices so MFA coverage reaches every person, not just the ones with a phone in hand.
Does QuickLaunch MFA replace Microsoft Entra or Duo?
No it completes them. Your existing identity provider gives you one MFA path; a campus needs several. QuickLaunch layers higher-ed-specific methods and adaptive rules on top of the stack you already run, so you add coverage without a rip-and-replace.
How do adaptive rules work?
Rules combine role and context. Role-based rules set the baseline a student, a faculty member, and a system administrator can each carry different method requirements. Contextual rules adjust in the moment: a sign-in from an unusual location or outside a geofence triggers step-up verification, while a routine sign-in from a known device stays frictionless.
When is MFA enforced?
From the very first moment. QuickLaunch enforces MFA enrollment during account activation students choose and register their method as part of claiming their account, before day one. There is no unprotected gap between account creation and MFA adoption, and no enrollment campaign chasing users after the fact.

The Student Identity Journey

One identity, from the day enrollment posts to everything IT can see.

Case Studies

Institutions Already on One Login

Ready for MFA That Fits Every Person on Campus?

Nine method families, adaptive rules, phoneless paths, and enrollment at activation live in as little as 30 days.

Request a Demo