Skip to main content
ChrisTan
Staff
Staff
September 23, 2025

Technical Tip: Adaptive MFA rule allow users can bypass the OTP verification

  • September 23, 2025
  • 0 replies
  • 643 views
Description This article describes the Adaptive MFA rule, which allows bypassing the OTP by subnet range or Known devices.
Scope FortiAuthenticator v6.6.3+.
Solution

Starting from v6.6.3, the FortiAuthenticator has the Adaptive MFA rule, to combines the trust subnet and known devices to give control over bypassing OTP.

 

The configuration process involves two key steps:

Defining Trusted Subnets: Trusted subnets (e.g., the corporate office IP range) are configured under: Authentication -> User Account Policies -> Trusted Subnets.

 

2025-09-22_14h51_21.png

   

Creating an Adaptive MFA Rule: Creating a new rule under the Adaptive MFA Rules section. The pre-defined trusted subnet can  be applied. 

 

2025-09-22_15h16_42.png

 

Once the Adaptive MFA rule is configured, it is applied by selecting it within a RADIUS policy. This means that when FortiAuthenticator processes an authentication request from a RADIUS client (like a FortiGate for VPN access), it will evaluate this rule.

 

If the user is connecting from a trusted subnet and on a known device, the OTP challenge will be bypassed, granting access with just a username and password.

 

2025-09-22_15h28_07.png