Zarv

Adaptive authentication (step-up)

Also known as: Step-up authentication · Risk-based authentication · Adaptive MFA · Context-aware authentication

Matching the authentication requirement to the risk of the moment: letting low-risk access flow without friction and asking for extra proof only when something departs from the norm.

Legal basis

NIST SP 800-63B — Authentication and Lifecycle Management (AAL)

Asking the same effort of everyone is bad on both sides: it blocks the legitimate customer and still does not stop a determined fraudster. Adaptive authentication (*risk-based*) calibrates friction to risk — the usual login, on the usual device, passes straight through; access from a new device, a different region, or a transaction outside the pattern triggers an extra step (*step-up*): a biometric, a second factor, a confirmation.

NIST SP 800-63B organizes this into assurance levels (AAL): the additional step raises certainty when the risk justifies it. What decides when to step up are device, behavioral and context signals — the same ones that detect account takeover — so that security shows up where it is needed and disappears where it would only get in the way.

Frequently asked questions

What is adaptive authentication (step-up)?

It is adjusting the authentication requirement to the risk of each access: low-risk access flows without friction, and only when something departs from the norm (new device, unusual location, atypical transaction) does the system ask for extra proof — the step-up, such as a biometric or a second factor.

Sources

Related terms

See it in practice

See risk before it costs you.

GDPR & CCPA Compliant · No commitment · Live in minutes