> ## Documentation Index
> Fetch the complete documentation index at: https://translations.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

> 多要素認証（MFA）の認証要素、ポリシー、ユースケースについて説明します。

# 多要素認証の認証要素

Auth0 は、<Tooltip tip="多要素認証（MFA）: SMS で送信されるコードなど、ユーザー名とパスワードに加えて別の認証要素を使用するユーザー認証プロセス。" cta="用語集を見る" href="/docs/ja-jp/glossary?term=multi-factor+authentication">多要素認証</Tooltip> (MFA) でユーザーアカウントへのアクセスを保護するための、さまざまなオプションや認証要素をサポートしています。

テナントで使用する MFA の認証要素を選択するには、[Auth0 Dashboard > Security > Multi-factor Auth](https://manage.auth0.com/#/security/mfa) に移動します。MFA を使用するには、テナントで少なくとも 1 つの認証要素を有効にする必要があります。利用可能な認証要素は、ご契約のプランによって異なります。詳細については、[Auth0 Pricing](https://auth0.com/pricing/) をご覧ください。

<div id="factors">
  ## 認証要素
</div>

Auth0 は、MFA で利用できる以下の認証要素をサポートしています。

<div id="push-notifications">
  ### プッシュ通知
</div>

ユーザーが事前に登録したデバイス (通常はスマートフォンやタブレット) にプッシュ通知を送信すると、ユーザーはボタンを押すだけで、アカウントへのアクセスをその場で許可または拒否できます。プッシュ認証要素は、iOS と Android の両方で利用できる **Auth0 Guardian** モバイルアプリで提供されています。詳しくは、[Auth0 Guardian](/docs/ja-jp/secure/multi-factor-authentication/auth0-guardian) をご覧ください。

顧客に別のアプリをダウンロードさせたくない場合は、既存のモバイルアプリに第 2 認証要素のワークフローを構築するための **Guardian SDK** も Auth0 が提供しています。詳しくは、[Install Guardian SDK](/docs/ja-jp/secure/multi-factor-authentication/multi-factor-authentication-developer-resources/install-guardian-sdk) をご覧ください。

<div id="sms-notifications">
  ### SMS通知
</div>

SMSでユーザーにワンタイムコードを送信し、ユーザーは認証を完了する前にそのコードの入力を求められます。詳しくは、[MFA の SMS 通知と音声通知を設定する](/docs/ja-jp/secure/multi-factor-authentication/multi-factor-authentication-factors/configure-sms-voice-notifications-mfa)をご覧ください。

<div id="voice-notifications">
  ### 音声通知
</div>

ワンタイムコードを音声通話でユーザーに伝え、ユーザーは認証を完了する前にそのコードを入力します。詳しくは、[MFA の SMS 通知と音声通知を設定する](/docs/ja-jp/secure/multi-factor-authentication/multi-factor-authentication-factors/configure-sms-voice-notifications-mfa)をご覧ください。

<div id="one-time-passwords">
  ### ワンタイムパスワード
</div>

ワンタイムパスワードを使用すると、Google Authenticator などの認証アプリをユーザーの個人用デバイスで使って、一定時間ごとに変化するワンタイムパスワードを生成し、それを第2の認証要素として入力して本人確認を行えます。詳しくは、[MFA の OTP 通知を設定する](/docs/ja-jp/secure/multi-factor-authentication/multi-factor-authentication-factors/configure-otp-notifications-for-mfa)を参照してください。

<div id="webauthn-with-security-keys">
  ### WebAuthn with Security Keys
</div>

ユーザーが FIDO 準拠の Security Keys (例: [Yubikey](https://www.yubico.com/)、[Google Titan](https://cloud.google.com/titan-security-key)) を使用して MFA を利用できるようにします。詳細については、[MFA 向けに WebAuthn with Security Keys を設定する](/docs/ja-jp/secure/multi-factor-authentication/fido-authentication-with-webauthn/configure-webauthn-security-keys-for-mfa)をご覧ください。

<div id="webauthn-with-device-biometrics">
  ### デバイス生体認証を使用したWebAuthn
</div>

MacBook の TouchBar、Windows Hello、iOS の Touch ID／Face ID、Android の指紋認証／顔認証などのプラットフォーム認証器を使用して、ユーザーが MFA を行えるようにします。詳しくは、[MFA 向けのデバイス生体認証を使用した WebAuthn を設定する](/docs/ja-jp/secure/multi-factor-authentication/fido-authentication-with-webauthn/configure-webauthn-device-biometrics-for-mfa)をご覧ください。

<div id="email-notifications">
  ### Email 通知
</div>

ユーザーが追加の[独立した認証要素](/docs/ja-jp/secure/multi-factor-authentication/enable-mfa#independent-factors)を登録済みであれば、メールで送信されるワンタイムパスワードを使用してMFAを行えるようにします。詳しくは、[MFA の Email 通知を設定する](/docs/ja-jp/secure/multi-factor-authentication/multi-factor-authentication-factors/configure-email-notifications-for-mfa)をお読みください。

<div id="cisco-duo-security">
  ### Cisco Duo Security
</div>

Cisco Duo は複数の認証方式に対応するプロバイダーであり、ユーザーが利用できる認証要素がこれだけの場合にのみ使用できます。Auth0 で MFA を管理するには、Duo アカウントを使用します。詳しくは、[MFA 用に Cisco Duo Security を設定する](/docs/ja-jp/secure/multi-factor-authentication/configure-cisco-duo-for-mfa)をご覧ください。

<div id="recovery-codes">
  ### リカバリーコード
</div>

リカバリーコードは、MFA の登録に使用したデバイスやアカウントにアクセスできなくなった場合に、ユーザーがアカウントへのアクセスを回復するための一意のコードです。詳しくは、[MFA のリカバリーコードを設定する](/docs/ja-jp/secure/multi-factor-authentication/configure-recovery-codes-for-mfa) を参照してください。

<div id="policies">
  ## ポリシー
</div>

ポリシーでは、特定のアカウントの所有者であることを証明するために、ユーザーに追加の手順を求めるタイミングを決定します。ポリシーを使って、許容可能なリスクのレベルを独自に定義できます。**Never**、**Use <Tooltip tip="Adaptive Multi-factor Authentication: ログイン試行の信頼度が低いと判断された場合にのみ、ユーザーに対してトリガーされる多要素認証（MFA）。" cta="用語集を見る" href="/docs/ja-jp/glossary?term=Adaptive+MFA">Adaptive MFA</Tooltip>**、**Always** から選択できます。

Auth0 Actions を使用すると、よりきめ細かな多要素認証の設定 (アプリケーションごと、ユーザーごとなど) を実現できます。詳しくは、[Auth0 Actions](/docs/ja-jp/customize/actions) をご覧ください。

<Callout icon="file-lines" color="#0EA5E9" iconType="regular">
  MFA に影響するルールは、Auth0 Dashboard のポリシー設定よりも優先されます。
</Callout>

詳しくは、[Defined Authentication Policies on OpenID.](http://openid.net/specs/openid-provider-authentication-policy-extension-1_0.html#rfc.section.4) をご覧ください。

<div id="use-cases">
  ## ユースケース
</div>

環境に応じて、MFA の管理方法は異なります。

* B2B: 顧客が自社のユーザーの MFA 認証要素を管理します。
* B2C: エンドユーザーが **My MFA Settings** ページで自分の MFA 認証要素を管理します。
* B2E: 管理者が自社のユーザーの MFA 認証要素を管理します。

MFA 認証要素を管理するユーザーインターフェースの構築に使用できる API エンドポイントについては、[Manage Authenticator Factors Using the MFA API.](/docs/ja-jp/secure/multi-factor-authentication/manage-mfa-auth0-apis/manage-authenticator-factors-mfa-api) を参照してください。

さまざまな種類のリソースへのアクセスを許可するアプリケーションでは、機密性の高いリソースにアクセスする際に、より強力な認証方式での認証をユーザーに要求できます。詳細については、[Step-Up Authentication](/docs/ja-jp/secure/multi-factor-authentication/step-up-authentication) を参照してください。

Action を作成するには、[Auth0 Dashboard > Actions > Flows](https://manage.auth0.com/#/actions/flows) に移動し、認証チャレンジをトリガーする条件を定義します。Actions を使用すると、特定のアプリケーションのユーザーや、特定のユーザーメタデータや IP 範囲を持つユーザーに対して MFA を必須にできます。そのほかのトリガーも使用できます。

コンテキスト MFA を追加すると、セキュリティ強化のために顧客に追加の認証チャレンジを求める任意の条件を定義できます。たとえば、地理的位置 (ジオフェンシング) 、使用しているネットワークのアドレスまたは種類 (IP フィルタリング) 、時刻、曜日、またはログインに使用する場所やデバイスの変化などです。

<div id="learn-more">
  ## 詳細
</div>

* [MFA のプッシュ通知を設定する](/docs/ja-jp/secure/multi-factor-authentication/multi-factor-authentication-factors/configure-push-notifications-for-mfa)
* [MFA の SMS 通知と音声通知を設定する](/docs/ja-jp/secure/multi-factor-authentication/multi-factor-authentication-factors/configure-sms-voice-notifications-mfa)
* [MFA の OTP 通知を設定する](/docs/ja-jp/secure/multi-factor-authentication/multi-factor-authentication-factors/configure-otp-notifications-for-mfa)
* [MFA の Email 通知を設定する](/docs/ja-jp/secure/multi-factor-authentication/multi-factor-authentication-factors/configure-email-notifications-for-mfa)
* [MFA 向けに Cisco Duo Security を設定する](/docs/ja-jp/secure/multi-factor-authentication/configure-cisco-duo-for-mfa)
* [MFA 向けに WebAuthn with Security Keys を設定する](/docs/ja-jp/secure/multi-factor-authentication/fido-authentication-with-webauthn/configure-webauthn-security-keys-for-mfa)
