Some SSO users are being asked for two forms of MFA

Incident Report for Dispel

Resolved

This issue has been resolved. All MFA enforcement flags are at the normal levels.
Posted Dec 20, 2023 - 20:19 EST

Update

Testing has confirmed an resolution to the issue. Integration checks are being performed currently.
Posted Dec 20, 2023 - 18:21 EST

Identified

The "Do not ask for Dispel MFA for SSO Users" flag is behaving inconsistently. This means that some users who previously were not required to have Dispel-based MFA may be prompted to set up or input additional MFA. This issue does not remove or lessen existing security settings and measures in any way.

Security implications: No security risk

Who this may impact: SSO users (if you sign into Dispel with Microsoft SSO, Okta, or another SSO integration)

How will this impact me: If you are an SSO user, you may experience the Dispel platform prompting you to input or set up an additional layer of MFA

We are implementing a fix and testing to confirm this resolves the issue.
Posted Dec 20, 2023 - 16:24 EST
This incident affected: https://dashboard.dispel.io (Dashboard).