Created on
10-14-2025
02:47 AM
Edited on
10-14-2025
03:31 AM
By
Jean-Philippe_P
This article explains the basic principles of Push Notification in the context of MFA in an easily understood manner.
FortiToken Mobile Application, FortiGate, FortiProxy, FortiAuthenticator.
Push Notifications are pop-up messages on mobile phones triggered by an application and provide updates/information about the application, anything from advertising to special offers to various timers.
Authenticator apps can use Push Notifications as a form of multi-factor-authentication (MFA). Essentially, when a user logs in, instead of being asked to enter a code as a second factor or present a certificate, the user receives a Push Notification and needs to confirm it.
A usual authentication flow with push notification includes the following components:
User/Client application. |
Application/Gateway. |
Authentication Server. |
The user and client application are connecting to the service in question. |
The gateway or application the user is connecting to. It requires the user to authenticate to proceed. |
The server validating the user's credentials and triggering push notification as multi-factor-authentication; may be the same device as Server/Application/Gateway. |
Example: FortiClient. |
Example: FortiGate. |
Example: FortiAuthenticator. |
Authentication, including push notification, follows roughly this flow (excluding SAML authentication):
Note on SAML Authentication:
The initial authentication flow for SAML differs significantly as the application/gateway (Service Provider in SAML context, SP) does not pass on the user credentials itself, but instead redirects the user to the Authentication Server (Identity Provider in SAML context, IdP). The SAML Identity Provider itself may trigger push notifications similar to the Authentication Server outlined here. A basic explanation of SAML authentication flow may be found here:
Technical Tip: A basic explanation of SAML authentication
Related articles:
Technical Tip: FortiToken Mobile push notification
Technical Tip: FortiAuthenticator Push Notification Work Flow
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.