Skip to content

Step-up Authentication

Certain areas of the VIP Dashboard can allow users access to secure information or to take actions that are not reversible. Because of this, VIP has implemented Step-up Authentication to protect those routes and actions including:

When performing sensitive actions or accessing higher-risk resources, users will be prompted to reauthenticate using one of the MFA methods that they configured through VIP Authentication. Doing so will allow them to undertake other protected actions or visit protected routes for 1 hour.

After an hour passes since reauthenticating, attempting to access a protected route or take a protected action will require the user to reauthenticate again.

Prerequisites

  • Step-up Authentication only applies to users with at minimum an Org admin role or an App admin role as protected routes and actions are only available for those roles.
  • Users must allow pop-ups in their browser from dashboard.wpvip.com to be able to take actions protected by Step-up Authentication.

Taking Protected Actions with Step-Up Authentication

Top ↑

Upon trying to take a protected action, users will be presented with a pop-up asking them to verify their identity using their preferred MFA method.

Example screenshot of the identity verification pop-up.

Users can select the Verify button to use this preferred MFA method or select Use Another Method if their preferred method of MFA is not available. Users may also choose to Return to the VIP Dashboard if they no longer wish to take a protected action.

While the identity verification pop-up is active, an overlay will be displayed over the VIP Dashboard, directing the user to the pop-up to verify their identity. If the pop-up has not been displayed, the user may select the Open authentication pop-up button to launch a new pop-up. Users may also select the Cancel button to return to the VIP Dashboard without reauthenticating again.

Example screenshot of the identity verification overlay.

If a user’s browser is blocking the pop-up from being displayed, an error will be displayed on the overlay, prompting the user to disable their pop-up blocker before attempting to launch the identity. verification pop-up again. Users may also have to check their browser settings to make sure that it allows pop-ups from dashboard.wpvip.com.

Once the user has successfully verified their identity, they may take protected actions and view protected resources for one hour before having to reauthenticate again.

Accessing Protected Routes with Step-Up Authentication

Top ↑

Upon trying to access a protected route in the VIP Dashboard, users will be redirected to verify their identity using their preferred MFA method.

Users can select the Verify button to use this preferred MFA method or select Use Another Method if their preferred method of MFA is not available. Users may also choose to Return to the VIP Dashboard if they no longer wish to access this protected route.

Once the user has successfully verified their identity, they may take protected actions and view protected resources for one hour before having to reauthenticate again.

Last updated: March 05, 2025