Enabling 2FA/MFA on the Esper Console: configure through SSO integration
Android
Title: Esper Console shows no 2FA option — enforce MFA through SSOWhen attempting to secure Esper Console logins with two-factor or multi-factor authentication, no built-in 2FA toggle exists in the Console settings. MFA is enforced exclusively through Single Sign-On (SSO) with your identity provider (IdP).
Why this happens
Esper delegates authentication — including MFA — to your organization's identity provider via SSO (SAML 2.0 or OIDC). This means MFA policies you already have in Okta, Azure AD, or Google Workspace apply automatically to Esper Console logins once SSO is configured. There is no separate MFA setting inside the Esper Console itself.
Before you start
- Confirm you have admin access to the Esper Console.
- Confirm your Esper subscription includes SSO. If unsure, contact Esper Support before proceeding.
- Confirm you have admin access to your IdP (Okta, Azure AD, Google Workspace, or another SAML 2.0 or OIDC-compatible provider).
Steps
- Open SSO settings in the Esper Console. Navigate to Company Settings → Single Sign-On (SSO) and complete the SSO configuration for your IdP. Follow the Set Up Single Sign-On (SSO) guide for step-by-step instructions specific to your provider.
- Log in to your identity provider's admin console. Locate the application you created for Esper during SSO setup, or the user group that has access to Esper.
- Enable MFA enforcement for the Esper application or user group. The exact steps vary by IdP — in Okta this is typically under Applications → [Esper App] → Sign On Policy; in Azure AD under Conditional Access → Policies; in Google Workspace under Security → 2-Step Verification. Consult your IdP's documentation if the path differs.
- Save and apply the MFA policy in your IdP, then log out of the Esper Console.
- Test the login flow. Attempt to sign in to the Esper Console via SSO. Your IdP should now interrupt the login and prompt for a second factor — such as an authenticator app code, push notification, or SMS — before granting access.
Verify: After completing the second factor, you should land on the Esper Console dashboard with no further prompts. Every subsequent SSO login should trigger the MFA challenge at the IdP step. If the MFA prompt does not appear, the policy has not been saved correctly in your IdP — re-check step 3.
If this doesn't resolve it
SSO setup fails or your IdP is not listed
Note the exact error message shown during SSO configuration in Company Settings → Single Sign-On (SSO). Contact Esper Support and include your enterprise (tenant) ID and the full error text.
SSO is configured but the MFA prompt never appears
The issue is almost always in the IdP configuration, not in Esper. Verify that MFA is enforced specifically for the Esper application or the relevant user group — not just for your IdP tenant globally. Consult your IdP's documentation or your internal IT administrator.
Your organization does not have an identity provider
An IdP is a prerequisite for MFA on the Esper Console. Provisioning an IdP is outside Esper's direct support scope, but Esper Support can advise on compatible providers. Submit a ticket describing your organization's setup and requirements.
Still need help?
Contact Esper Support with the following information: your enterprise (tenant) ID, the name and version of your IdP, the SSO protocol in use (SAML 2.0 or OIDC), and any error messages or screenshots from both the Esper Console and your IdP admin console.
Still need help?
If the steps above don't resolve the issue, submit a support ticket with your device model, Android version, Esper Agent version, and a description of what you've already tried — this helps the support team investigate without a follow-up.
Please sign in to leave a comment.
Comments
0 comments