Skip to main content
Workflow

Emergency access for shared MFA

Incident workflow for temporary shared MFA viewer expansion: authorization, time limits, audit logging, incident evidence, and post-incident revocation.

Emergency access principles

Emergency access is temporary elevation of second-factor visibility, not sharing passwords in chat. Align with shared MFA policy and lockout risk guide.

Anti-patterns to avoid

  • Posting TOTP screenshots in public Slack channels.
  • Leaving emergency viewers for weeks after incidents.
  • Adding entire company as viewers preemptively.

Operationalize this workflow with MultiMFA

Governed SMS and TOTP for collective logins—14-day trial.

Emergency access steps

Time-boxed viewer expansion during incidents.

  1. Declare incident & approver

    Incident commander or security lead authorizes MFA expansion in ticket.

  2. Add time-boxed viewers

    MultiMFA admin adds named responders—document start time.

  3. Use viewer dashboard only

    No OTP in public channels; reference runbook link.

  4. Complete vendor actions

    Perform recovery/billing/cloud tasks under change control.

  5. Revoke & retrospective

    Remove temporary viewers; note gaps for policy updates.

Glossary

Key terms in this guide

Operational definitions for shared MFA vocabulary—written for security and IT teams, not dictionary-only summaries.

Workflow FAQ

Does MultiMFA replace our IdP MFA?
No. MultiMFA governs second factors for shared operational logins. Workforce SSO MFA remains on your identity provider.
How fast can we revoke access?
Admins remove viewers/recipients in MultiMFA immediately—faster than resetting vendor MFA on personal phones across many apps.
Can emergency access bypass MFA entirely?
Only via vendor break-glass mechanisms—not by disabling MFA casually. This workflow governs how teams obtain codes during incidents.

More questions? Contact support or read our security overview.

Reduce operational MFA friction

Named viewers, admin revoke, and audit-friendly workflows.