| MFA Configured State | Checks whether the user has already configured MFA and routes to the selected method. |
| MFA Unconfigured State | Checks which MFA methods the user has not yet configured for mandatory enrollment flows. |
| Configure MFA | Presents available MFA methods for initial enrollment; supports Mandatory or Optional flows. |
| Configure Authenticator | Sets up the Authenticator app (TOTP) MFA method with a QR code. |
| Configure Security Question | Sets up the Security Question MFA method. |
| Configure Push Notification | Sets up the Push Notification MFA method via the LoginRadius Authenticator app. |
| Verify Email/SMS OTP | Verifies an OTP sent by email or SMS. |
| Verify Authenticator | Verifies a TOTP code from the user's authenticator app. |
| Verify Security Question | Verifies the user's answer to a configured security question. |
| Verify Backup Code | Verifies a backup code for MFA recovery. |
| Verify Duo Authentication | Verifies a Duo Security authentication response. |
| Send Push Notification | Sends a push notification to the user's registered mobile device. |
| Verify Push Notification | Polls for the user's approval or denial of a push notification. |
| Update MFA Phone | Updates the phone number used for SMS OTP MFA. |
| Update MFA Options | Allows users to add or update their registered MFA options. |
| Update Security Answer | Updates the user's answer for the configured security question. |
| Download Backup Code | Allows users to download backup codes for the Authenticator MFA method. |
| Reset Authenticator | Resets the user's configured Authenticator app registration. |
| Reset Backup Code | Generates a new set of backup codes, invalidating the previous set. |