netzbegruenung / keycloak-mfa-plugins

Keycloak plugins for MFA (enforce MFA, SMS authentication step, native app integration)
Apache License 2.0
45 stars 12 forks source link

Introduce verification step #16

Closed svenseeberg closed 2 years ago

svenseeberg commented 2 years ago

A phone number should be verified before the user should be able to use it as second factor. This is similar to TOTP, where the user needs to enter the first OTP, before TOTP becomes active as a second factor.

Procedure: