Product Security

Multi-Factor Authentication

Workspaces that do not federate through SAML can require multi-factor authentication for their users. Where you use your own identity provider, your MFA policy applies and Harmony enforces it through the SSO session.

Framework requirements this speaks to

  • ISO 27001 A.5.17 (authentication information)
  • ISO 27001 A.8.5 (secure authentication)

Framework references are indicative: they show which requirement a control speaks to, so you can line it up against your own checklist. The authoritative mapping is the one in our SOC 2 report and our ISO 27001 Statement of Applicability, both available under NDA.

Need the evidence behind this?

Our SOC 2 report and ISO 27001 Statement of Applicability are the authoritative record. Both are available under NDA, by email - we do not host them as downloads.