Adaptive authentication (step-up)
Also known as: Step-up authentication · Risk-based authentication · Adaptive MFA · Context-aware authentication
Matching the authentication requirement to the risk of the moment: letting low-risk access flow without friction and asking for extra proof only when something departs from the norm.
Legal basis
NIST SP 800-63B — Authentication and Lifecycle Management (AAL)
Asking the same effort of everyone is bad on both sides: it blocks the legitimate customer and still does not stop a determined fraudster. Adaptive authentication (*risk-based*) calibrates friction to risk — the usual login, on the usual device, passes straight through; access from a new device, a different region, or a transaction outside the pattern triggers an extra step (*step-up*): a biometric, a second factor, a confirmation.
NIST SP 800-63B organizes this into assurance levels (AAL): the additional step raises certainty when the risk justifies it. What decides when to step up are device, behavioral and context signals — the same ones that detect account takeover — so that security shows up where it is needed and disappears where it would only get in the way.
Frequently asked questions
What is adaptive authentication (step-up)?
It is adjusting the authentication requirement to the risk of each access: low-risk access flows without friction, and only when something departs from the norm (new device, unusual location, atypical transaction) does the system ask for extra proof — the step-up, such as a biometric or a second factor.