Multi‑Factor Authentication (MFA) is a security measure that helps protect user accounts by requiring more than one method of verification when signing in. In addition to a username and password, MFA requires a second factor, such as a verification code making it much harder for unauthorized users to access ServiceNow accounts. MFA is required to reduce the risk of account compromise, protect sensitive staff and organizational data, and meet security and compliance standards.
By the end of this article, you will understand:
By default, ServiceNow uses email‑based verification as the MFA method. This default setting applies automatically but can be changed to another approved MFA method based on user needs and security requirements.
While MFA is mandatory for all users, users can choose from several approved authentication methods. These include a time‑based one‑time password (TOTP) authenticator app (such as Google Authenticator), a biometric authenticator (for example, Windows Hello or Apple Touch ID), a FIDO2‑compliant hardware authenticator (such as a YubiKey), or a passkey.