0Pricing
OAuth2 & OpenID Connect Deep Dive · Lektion

Multi-Faktor-Authentifizierung (MFA)

Erkunden Sie, wie MFA in OIDC-Flows integriert wird, um die Benutzerauthentifizierung um eine zusätzliche Sicherheitsebene zu erweitern.

Multi-Faktor-Authentifizierung (MFA) ist eine kostenlose OAuth2 & OpenID Connect Deep Dive-Lektion auf CoddyKit. Dies ist Lektion 3 von 4. Du kannst die komplette Lektion unten kostenlos lesen – dann übst du sie direkt im Browser mit einem integrierten Code-Editor und einem KI-Tutor rund um die Uhr. Sie ist Teil des OAuth2 & OpenID Connect Deep Dive-Lernpfads, und dein Fortschritt wird über Web und CoddyKit-App synchronisiert. Der OAuth2 & OpenID Connect Deep Dive-Kurs umfasst insgesamt 4 Lektionen.

Teile dieser Lektion wurden noch nicht übersetzt und werden auf Englisch angezeigt.

What is Multi-Factor Authentication?

Multi-Factor Authentication (MFA) adds an extra layer of security to user accounts beyond just a password.

Instead of relying on a single piece of evidence (like "something you know"), MFA requires two or more verification methods from different categories.

The "Factors" of MFA

MFA typically combines factors from these categories:

  • Something you know: A password or PIN.
  • Something you have: A phone, hardware token, or authenticator app.
  • Something you are: A fingerprint, face scan, or voice recognition.

Using multiple factors makes it much harder for unauthorized users to gain access.

Why MFA in OIDC?

OpenID Connect (OIDC) itself doesn't perform MFA. Instead, it acts as a secure way for an Identity Provider (IdP) to tell your application whether a user authenticated with MFA.

Your application can then use this information to make informed authorization decisions.

Introducing ACR Values

In OIDC, "Authentication Context Class References" (ACR values) are used to specify how a user was authenticated.

These are unique identifiers that represent different levels or methods of authentication, including whether MFA was used.

Requesting a Specific ACR Level

When your application initiates an OIDC authorization request, it can include the acr_values parameter.

This parameter tells the Identity Provider that your application prefers or requires a specific authentication context, such as MFA.

Example: Requesting MFA

Here's a simplified example of an OIDC authorization URL requesting an MFA context. The specific acr_values like "mfa" or "https://acr.example.com/mfa" depend on the Identity Provider's configuration.

public class Main {
  public static void main(String[] args) {
    String authUrl = "https://idp.example.com/authorize?"
      + "response_type=code"
      + "&client_id=my_client_app"
      + "&redirect_uri=https://app.example.com/callback"
      + "&scope=openid%20profile"
      + "&acr_values=mfa";
    System.out.println("Authorization URL:\n" + authUrl);
  }
}

Receiving MFA Status in the ID Token

After successful authentication, the Identity Provider returns an ID Token to your application. This token contains various claims about the user and their authentication session.

The acr claim within the ID Token indicates the actual authentication context class reference that was satisfied.

Example: Decoding an ID Token with 'acr'

Let's imagine an ID Token payload after a user authenticated with MFA. The acr claim would be present, confirming the authentication method used.

In a real application, you would decode and validate the JWT to read this claim.

public class Main {
  public static void main(String[] args) {
    // Example of a decoded ID Token payload
    // In a real app, you'd parse a JWT.
    String idTokenPayload = "{\n  \"iss\": \"https://idp.example.com\",\n  \"sub\": \"user123\",\n  \"aud\": \"my_client_app\",\n  \"exp\": 1678886400,\n  \"iat\": 1678882800,\n  \"auth_time\": 1678882700,\n  \"acr\": \"mfa\",\n  \"amr\": [\"pwd\", \"otp\"]\n}";
    System.out.println("Simulated ID Token Payload:\n" + idTokenPayload);
  }
}

Enforcing MFA-Based Policies

Once your application receives and validates the ID Token, it can check the acr claim.

Based on this, you can implement conditional access policies. For example, if a user tries to access sensitive data, and the acr claim doesn't indicate MFA, you might deny access or prompt for re-authentication.

Quick Check

Which OIDC parameter is used by a client application to request that a user authenticates with Multi-Factor Authentication?

Recap: MFA & OIDC

We've learned that MFA adds critical security layers by requiring multiple authentication factors.

OIDC doesn't perform MFA itself, but it provides a standardized way (via acr_values in requests and the acr claim in ID Tokens) for applications to request and receive information about the authentication context, enabling robust, MFA-aware security policies.

Häufig gestellte Fragen

Ist die Lektion „Multi-Faktor-Authentifizierung (MFA)“ kostenlos?

Ja — der vollständige Text von „Multi-Faktor-Authentifizierung (MFA)“ ist hier im Web kostenlos zu lesen. Um sie interaktiv zu üben (integrierter Code-Editor und 24/7 KI-Tutor) und den Rest des OAuth2 & OpenID Connect Deep Dive-Kurses freizuschalten, upgrade auf CoddyKit PRO. Der OAuth2 & OpenID Connect Deep Dive-Kurs umfasst insgesamt 4 Lektionen.

Was lerne ich in „Multi-Faktor-Authentifizierung (MFA)“?

Erkunden Sie, wie MFA in OIDC-Flows integriert wird, um die Benutzerauthentifizierung um eine zusätzliche Sicherheitsebene zu erweitern. Du übst OAuth2 & OpenID Connect Deep Dive mit praktischem Code, den du direkt im Browser ausführst, und ein 24/7 KI-Tutor beantwortet deine Fragen während du die Lektion bearbeitest.

Brauche ich Erfahrung, um OAuth2 & OpenID Connect Deep Dive zu starten?

Keine Vorkenntnisse erforderlich. OAuth2 & OpenID Connect Deep Dive auf CoddyKit ist für Anfänger bis fortgeschrittene Lernende strukturiert, sodass du hier starten oder von Anfang an beginnen und in deinem eigenen Tempo voranschreiten kannst. Dies ist Lektion 3 von 4.

Wie lange dauert die Lektion „Multi-Faktor-Authentifizierung (MFA)“?

Die meisten CoddyKit-Lektionen dauern etwa 5–10 Minuten. Jede ist kompakt und interaktiv, sodass du stetig Fortschritte machst und genau dort weitermachst, wo du aufgehört hast – im Web und in der App.

Kann ich in dieser OAuth2 & OpenID Connect Deep Dive-Lektion Code schreiben und ausführen?

Ja. Jede OAuth2 & OpenID Connect Deep Dive-Lektion enthält einen integrierten Code-Editor, sodass du echten Code direkt in deinem Browser schreibst und ausführst und sofort KI-Feedback erhältst — ohne lokale Einrichtung erforderlich.

Alle Lektionen in diesem Kurs

  1. Integration mit Identity Providern
  2. Microservices- und API-Gateway-Sicherheit
  3. Multi-Faktor-Authentifizierung (MFA)
  4. Single Sign-On über mehrere Anwendungen
← Zurück zu OAuth2 & OpenID Connect Deep Dive