> ## Documentation Index
> Fetch the complete documentation index at: https://translations.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

> Auth0 のリスク評価と総合信頼度スコアに基づいて、信頼度の低いログインに対して Adaptive MFA を有効にする方法を説明します。

# Adaptive MFA を有効にする

<Card title="始める前に">
  * Adaptive MFA アドオン付きの Enterprise プランに加入します。詳細は [Auth0 Pricing](https://auth0.com/pricing/) を参照してください。
  * Database または Active Directory 接続を設定して有効にします。
  * 少なくとも 1 つの MFA 認証要素を設定して有効にします。
</Card>

Auth0 がログイン試行にリスクがあると判断した場合に <Tooltip tip="Adaptive MFA: ログイン試行が信頼度の低いログインと判断された場合にのみ、ユーザーに対してトリガーされる多要素認証 (MFA)。" cta="用語集を見る" href="/docs/ja-jp/glossary?term=Adaptive+MFA">Adaptive MFA</Tooltip> を使用して <Tooltip tip="Adaptive MFA: ログイン試行が信頼度の低いログインと判断された場合にのみ、ユーザーに対してトリガーされる多要素認証 (MFA)。" cta="用語集を見る" href="/docs/ja-jp/glossary?term=MFA">MFA</Tooltip> を要求し、すべてのログイントランザクションのリスク評価をテナントログに記録します。

<div id="enable-adaptive-mfa">
  ## Adaptive MFA を有効にする
</div>

<Tooltip tip="Auth0 Dashboard: サービスを設定するための Auth0 のメイン製品です。" cta="用語集を表示" href="/docs/ja-jp/glossary?term=Auth0+Dashboard">Auth0 Dashboard</Tooltip> または Auth0 の <Tooltip tip="Auth0 Dashboard: サービスを設定するための Auth0 のメイン製品です。" cta="用語集を表示" href="/docs/ja-jp/glossary?term=Management+API">Management API</Tooltip> で Adaptive MFA を有効にできます。

<Tabs>
  <Tab title="Auth0 Dashboard">
    1. [**Auth0 Dashboard > Security > Multi-factor Auth**](https://manage.auth0.com/#/security/mfa) に移動します。

    <Frame>
      <img src="https://mintcdn.com/translations/pvjQqAy3EB2TK6NP/docs/images/cdy7uua7fh8z/4IlQi0LXOPJdYjOuo09xtE/944ce27c115cb43133aac78d9b6b7886/MFA_Factors_-_English.png?fit=max&auto=format&n=pvjQqAy3EB2TK6NP&q=85&s=3bf6a8171e084f5a7278f3b4fc81f8d1" alt="Auth0 Dashboard Security Multi-factor Auth Adaptive MFA ポリシー" width="839" height="1076" data-path="docs/images/cdy7uua7fh8z/4IlQi0LXOPJdYjOuo09xtE/944ce27c115cb43133aac78d9b6b7886/MFA_Factors_-_English.png" />
    </Frame>

    2. **Factors** セクションで、少なくとも 1 つの MFA 認証要素を有効にして設定します。詳しくは、[多要素認証の認証要素](/docs/ja-jp/secure/multi-factor-authentication/multi-factor-authentication-factors) をご覧ください。

    3. **Define policies** セクションで **Require Multi-factor Auth** を見つけ、**Use Adaptive MFA** を選択します。リスク評価は自動的に有効になり、テナントログに記録されます。

    4. **Device Trust Duration** フィールドで、ユーザーが MFA での認証を再度求められるまで、デバイスを信頼済みとして扱う日数を設定します。デフォルトの期間は 30 日ですが、ユーザーに対するチャレンジの回数は増減できます。

           <Warning>
             デバイスの記憶期間を Okta の標準推奨設定より長く変更したことによりセキュリティ体制が低下した場合、その責任は Auth0 のお客様が負うものとします。
           </Warning>

       * 信頼済みデバイスの期間は 1 日から 365 日の範囲で設定できます。
       * 期間を変更した場合、新しい期間の値は、ユーザーが次回ログインしたときにそのユーザーのデバイスに適用されます。

    5. **Save** を選択します。

    <Callout icon="file-lines" color="#0EA5E9" iconType="regular">
      [Identifier First Authentication](/docs/ja-jp/authenticate/login/auth0-universal-login/identifier-first) の認証要素 `email` を使用している場合は、[Auth0 Dashboard > Database Connections > Authentication Methods](https://manage.auth0.com/#/connections/database) でメール属性を更新する必要があります。メール設定タブで、メール属性が有効になっていることを確認してください。次に、**Allow Signup** を **Required** に設定し、ユーザープロファイルで email の **Require** を有効にします。

      <Frame>
        <img src="https://mintcdn.com/translations/xwVvTWJUElMm5YAK/docs/images/cdy7uua7fh8z/ql7yYX1GnJaiPQnjQQBTs/7ce5b2a51be21e4b3b6dc65b97b4b3eb/Email_Config_-_English.png?fit=max&auto=format&n=xwVvTWJUElMm5YAK&q=85&s=1be4f59f3df62b371d3a23938f035a6c" alt="Auth0 Dashboard > Authentication > Database Connections > Authentication Methods" data-og-width="532" width="532" data-og-height="829" height="829" data-path="docs/images/cdy7uua7fh8z/ql7yYX1GnJaiPQnjQQBTs/7ce5b2a51be21e4b3b6dc65b97b4b3eb/Email_Config_-_English.png" data-optimize="true" data-opv="3" srcset="https://mintcdn.com/translations/xwVvTWJUElMm5YAK/docs/images/cdy7uua7fh8z/ql7yYX1GnJaiPQnjQQBTs/7ce5b2a51be21e4b3b6dc65b97b4b3eb/Email_Config_-_English.png?w=280&fit=max&auto=format&n=xwVvTWJUElMm5YAK&q=85&s=53577224debb54a3c29afe4a53fcfed8 280w, https://mintcdn.com/translations/xwVvTWJUElMm5YAK/docs/images/cdy7uua7fh8z/ql7yYX1GnJaiPQnjQQBTs/7ce5b2a51be21e4b3b6dc65b97b4b3eb/Email_Config_-_English.png?w=560&fit=max&auto=format&n=xwVvTWJUElMm5YAK&q=85&s=78f8536d77a47f72aec3180c87a12faa 560w, https://mintcdn.com/translations/xwVvTWJUElMm5YAK/docs/images/cdy7uua7fh8z/ql7yYX1GnJaiPQnjQQBTs/7ce5b2a51be21e4b3b6dc65b97b4b3eb/Email_Config_-_English.png?w=840&fit=max&auto=format&n=xwVvTWJUElMm5YAK&q=85&s=50d4a9a2ac8abfc0e4ea2053b386ea9c 840w, https://mintcdn.com/translations/xwVvTWJUElMm5YAK/docs/images/cdy7uua7fh8z/ql7yYX1GnJaiPQnjQQBTs/7ce5b2a51be21e4b3b6dc65b97b4b3eb/Email_Config_-_English.png?w=1100&fit=max&auto=format&n=xwVvTWJUElMm5YAK&q=85&s=bb0a84b32b60fe347e7f2c7f1daecfaa 1100w, https://mintcdn.com/translations/xwVvTWJUElMm5YAK/docs/images/cdy7uua7fh8z/ql7yYX1GnJaiPQnjQQBTs/7ce5b2a51be21e4b3b6dc65b97b4b3eb/Email_Config_-_English.png?w=1650&fit=max&auto=format&n=xwVvTWJUElMm5YAK&q=85&s=df8a2a170bf37e9d1edc481be3517666 1650w, https://mintcdn.com/translations/xwVvTWJUElMm5YAK/docs/images/cdy7uua7fh8z/ql7yYX1GnJaiPQnjQQBTs/7ce5b2a51be21e4b3b6dc65b97b4b3eb/Email_Config_-_English.png?w=2500&fit=max&auto=format&n=xwVvTWJUElMm5YAK&q=85&s=aa6805efb05f39123ea487b8beecda7e 2500w" />
      </Frame>
    </Callout>
  </Tab>

  <Tab title="Management API">
    1. `update:mfa_policies` スコープを持つ [Management API アクセストークン](/docs/ja-jp/secure/tokens/access-tokens/management-api-access-tokens/get-management-api-access-tokens-for-production) を取得します。

    2. 適切なペイロードを使用して、Management API の [Set the multi-factor authentication policies](https://auth0.com/docs/api/management/v2/guardian/put-policies) エンドポイントを呼び出します。

    3. **Device Trust Duration** をデフォルトの 30 日から変更する場合は、[Update New Device Accessor](https://auth0.com/docs/api/management/v2/risk-assessments/patch-new-device) を呼び出します。Management API アクセストークンには、次のスコープを追加する必要があります。
       * `read:attack_protection`
       * `update:attack_protection`
           <Warning>
             デバイスの記憶期間を Okta の標準推奨設定より長く変更したことによりセキュリティ体制が低下した場合、その責任は Auth0 のお客様が負うものとします。
           </Warning>
  </Tab>
</Tabs>

<div id="enable-adaptive-mfa-risk-assessment">
  ## Adaptive MFA リスク評価を有効にする
</div>

Adaptive MFA をまだ有効にする段階ではないものの、ログイン時の挙動を分析できるように学習を開始したい場合は、Adaptive MFA リスク評価だけを個別に有効にできます。

1. [Auth0 Dashboard > Security > Multi-factor Auth](https://manage.auth0.com/#/security/mfa) に移動します。
2. **Define policies** セクションを探します。
3. **MFA Risk Assessors** で、**Enable Adaptive MFA Risk Assessment** を選択します。
4. **Save** を選択します。

<div id="customize-adaptive-mfa">
  ## Adaptive MFA のカスタマイズ
</div>

セキュリティを確保しながらユーザーに最適な体験を提供できるよう、Adaptive MFA の動作をカスタマイズできます。詳しくは、[Adaptive MFA のカスタマイズ](/docs/ja-jp/secure/multi-factor-authentication/adaptive-mfa/customize-adaptive-mfa) をご覧ください。

<Callout icon="file-lines" color="#0EA5E9" iconType="regular">
  MFA をトリガーする Actions は、デフォルトの Adaptive MFA の動作よりも優先されます。
</Callout>

<div id="limitations">
  ## 制限事項
</div>

テナントログで評価情報を利用できるのは、対話型フローのみです。Auth0 は、Adaptive MFA が有効になっていない <Tooltip tip="リソース所有者: 保護されたリソースへのアクセスを許可できるエンティティ（ユーザーやアプリケーションなど）。" cta="用語集を見る" href="/docs/ja-jp/glossary?term=Resource+Owner">リソース所有者</Tooltip> Password Grant (ROPG) フローの評価情報の記録をサポートしていません。認証フローの制限事項の詳細については、[Adaptive MFA](/docs/ja-jp/secure/multi-factor-authentication/adaptive-mfa) をご覧ください。

<div id="learn-more">
  ## 詳細はこちら
</div>

* [Adaptive MFA のカスタマイズ](/docs/ja-jp/secure/multi-factor-authentication/adaptive-mfa/customize-adaptive-mfa)
* [Adaptive MFA のログイベント](/docs/ja-jp/secure/multi-factor-authentication/adaptive-mfa/adaptive-mfa-log-events)
* [多要素認証の認証要素](/docs/ja-jp/secure/multi-factor-authentication/multi-factor-authentication-factors)
