Skip to content

How to Use Location and Device for 2FA

August 5, 2021 · 1 min read

  • Tutorials

Leverage contextual information to implement intelligent authentication workflows in the Gluu Server.

Two-factor authentication (2FA) is proven to increase account security, but it also adds friction to the user experience.

Frequently 2FA is best employed only when there’s a reasonable likelihood of fraud–for example, if the user’s device or IP address is unrecognized.

To implement custom policies and logic for authentication in the Gluu Server, you can use person authentication scripts. In fact, this specific policy, i.e. checking for unrecognized devices and locations, is supported OOTB in our self-service 2FA product, Casa.

But this type of policy can be implemented in any authentication script. And in this short tutorial, we’ll dissect the Casa interception script to show how you can apply similar policies in your own scripts.

#Device details

The default Gluu login page template uses the platform detection library, bestie.js, to gather operating system and browser details (i.e. device details) for each user authenticating at the service:

1

2

3

4