> ## Documentation Index
> Fetch the complete documentation index at: https://translations.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

> Auth0 のリスク評価と総合信頼度スコアに基づいて、信頼度の低いログインに対して Adaptive MFA を有効にする方法を説明します。

# Adaptive MFA を有効にする

<Card title="始める前に">
  * Adaptive MFA アドオンを含む Enterprise Plan に登録します。詳細については、[Auth0 Pricing](https://auth0.com/pricing/) を参照してください。
  * Database または Active Directory 接続を設定して有効にします。
  * 少なくとも 1 つの MFA 要素を設定して有効にします。
</Card>

<Tooltip tip="Adaptive Multi-factor Authentication: 試行されたログインが信頼度の低いログインであると判断された場合にのみ、ユーザーに対して実行される多要素認証（MFA）。" cta="用語集を見る" href="/ja/docs/glossary?term=Adaptive+MFA">Adaptive MFA</Tooltip> を使用すると、Auth0 がログイン試行を高リスクと判断した場合に <Tooltip tip="Adaptive Multi-factor Authentication: 試行されたログインが信頼度の低いログインであると判断された場合にのみ、ユーザーに対して実行される多要素認証（MFA）。" cta="用語集を見る" href="/ja/docs/glossary?term=MFA">MFA</Tooltip> を要求し、すべてのログイン トランザクションのリスク評価をテナントログに記録できます。

<div id="enable-adaptive-mfa">
  ## Adaptive MFA を有効にする
</div>

<Tooltip tip="Auth0 Dashboard: サービスを設定するための Auth0 の主要製品です。" cta="用語集を見る" href="/ja/docs/glossary?term=Auth0+Dashboard">Auth0 Dashboard</Tooltip> または Auth0 の <Tooltip tip="Auth0 Dashboard: サービスを設定するための Auth0 の主要製品です。" cta="用語集を見る" href="/ja/docs/glossary?term=Management+API">Management API</Tooltip> で Adaptive MFA を有効にできます。

<Tabs>
  <Tab title="Dashboard">
    1. [**Dashboard > Security > Multi-factor Auth**](https://manage.auth0.com/#/security/mfa) に移動します。

    <Frame>
      <img src="https://mintcdn.com/translations/pvjQqAy3EB2TK6NP/docs/images/cdy7uua7fh8z/4IlQi0LXOPJdYjOuo09xtE/944ce27c115cb43133aac78d9b6b7886/MFA_Factors_-_English.png?fit=max&auto=format&n=pvjQqAy3EB2TK6NP&q=85&s=3bf6a8171e084f5a7278f3b4fc81f8d1" alt="Auth0 Dashboard Security Multi-factor Auth Adaptive MFA Policy" width="839" height="1076" data-path="docs/images/cdy7uua7fh8z/4IlQi0LXOPJdYjOuo09xtE/944ce27c115cb43133aac78d9b6b7886/MFA_Factors_-_English.png" />
    </Frame>

    2. **Factors** セクションで、少なくとも 1 つの MFA 要素を有効にして設定します。詳細については、[多要素認証の認証要素](/ja/docs/secure/multi-factor-authentication/multi-factor-authentication-factors) を参照してください。

    3. **Define policies** セクションで **Require Multi-factor Auth** を見つけて、**Use Adaptive MFA** を選択します。リスク評価は自動的に有効になり、テナントログに記録されます。

    4. **Device Trust Duration** フィールドで、ユーザーが再度 MFA で認証する必要が生じるまで、デバイスを信頼済みとして保持する日数を設定します。デフォルトの期間は 30 日ですが、ユーザーに求めるチャレンジの回数は増減できます。

           <Warning>
             デバイスの記憶期間を Okta の標準推奨設定より長く変更したことで生じるセキュリティ体制の低下については、Auth0 のお客様が責任を負います。
           </Warning>

       * 信頼済みデバイスの有効期間は 1 日から 365 日の範囲で設定できます。
       * 期間を変更すると、新しい期間の値はユーザーが次回ログインしたときにそのユーザーのデバイスに適用されます。

    5. **Save** を選択します。

    <Callout icon="file-lines" color="#0EA5E9" iconType="regular">
      [Identifier First Authentication](/ja/docs/authenticate/login/auth0-universal-login/identifier-first) の要素 `email` を使用している場合は、[Dashboard > Database Connections > Authentication Methods](https://manage.auth0.com/#/connections/database) でメールアドレス属性を更新する必要があります。Email Configuration タブで、メールアドレス属性が有効になっていることを確認します。次に、**Allow Signup** を **Required** に設定し、ユーザープロフィールで **Require** email を有効にします。

      <Frame>
        <img src="https://mintcdn.com/translations/xwVvTWJUElMm5YAK/docs/images/cdy7uua7fh8z/ql7yYX1GnJaiPQnjQQBTs/7ce5b2a51be21e4b3b6dc65b97b4b3eb/Email_Config_-_English.png?fit=max&auto=format&n=xwVvTWJUElMm5YAK&q=85&s=1be4f59f3df62b371d3a23938f035a6c" alt="Auth0 Dashboard > Authentication > Database Connections > Authentication Methods" data-og-width="532" width="532" data-og-height="829" height="829" data-path="docs/images/cdy7uua7fh8z/ql7yYX1GnJaiPQnjQQBTs/7ce5b2a51be21e4b3b6dc65b97b4b3eb/Email_Config_-_English.png" data-optimize="true" data-opv="3" srcset="https://mintcdn.com/translations/xwVvTWJUElMm5YAK/docs/images/cdy7uua7fh8z/ql7yYX1GnJaiPQnjQQBTs/7ce5b2a51be21e4b3b6dc65b97b4b3eb/Email_Config_-_English.png?w=280&fit=max&auto=format&n=xwVvTWJUElMm5YAK&q=85&s=53577224debb54a3c29afe4a53fcfed8 280w, https://mintcdn.com/translations/xwVvTWJUElMm5YAK/docs/images/cdy7uua7fh8z/ql7yYX1GnJaiPQnjQQBTs/7ce5b2a51be21e4b3b6dc65b97b4b3eb/Email_Config_-_English.png?w=560&fit=max&auto=format&n=xwVvTWJUElMm5YAK&q=85&s=78f8536d77a47f72aec3180c87a12faa 560w, https://mintcdn.com/translations/xwVvTWJUElMm5YAK/docs/images/cdy7uua7fh8z/ql7yYX1GnJaiPQnjQQBTs/7ce5b2a51be21e4b3b6dc65b97b4b3eb/Email_Config_-_English.png?w=840&fit=max&auto=format&n=xwVvTWJUElMm5YAK&q=85&s=50d4a9a2ac8abfc0e4ea2053b386ea9c 840w, https://mintcdn.com/translations/xwVvTWJUElMm5YAK/docs/images/cdy7uua7fh8z/ql7yYX1GnJaiPQnjQQBTs/7ce5b2a51be21e4b3b6dc65b97b4b3eb/Email_Config_-_English.png?w=1100&fit=max&auto=format&n=xwVvTWJUElMm5YAK&q=85&s=bb0a84b32b60fe347e7f2c7f1daecfaa 1100w, https://mintcdn.com/translations/xwVvTWJUElMm5YAK/docs/images/cdy7uua7fh8z/ql7yYX1GnJaiPQnjQQBTs/7ce5b2a51be21e4b3b6dc65b97b4b3eb/Email_Config_-_English.png?w=1650&fit=max&auto=format&n=xwVvTWJUElMm5YAK&q=85&s=df8a2a170bf37e9d1edc481be3517666 1650w, https://mintcdn.com/translations/xwVvTWJUElMm5YAK/docs/images/cdy7uua7fh8z/ql7yYX1GnJaiPQnjQQBTs/7ce5b2a51be21e4b3b6dc65b97b4b3eb/Email_Config_-_English.png?w=2500&fit=max&auto=format&n=xwVvTWJUElMm5YAK&q=85&s=aa6805efb05f39123ea487b8beecda7e 2500w" />
      </Frame>
    </Callout>
  </Tab>

  <Tab title="Management API">
    1. `update:mfa_policies` スコープを持つ [Management API アクセストークン](/ja/docs/secure/tokens/access-tokens/management-api-access-tokens/get-management-api-access-tokens-for-production) を取得します。

    2. 適切なペイロードを指定して、Management API の [Set the multi-factor authentication policies](https://auth0.com/docs/api/management/v2/guardian/put-policies) エンドポイントを呼び出します。

    3. **Device Trust Duration** をデフォルトの 30 日から変更する場合は、[Update New Device Accessor](https://auth0.com/docs/api/management/v2/risk-assessments/patch-new-device) を呼び出します。Management API アクセストークンには、次のスコープを追加する必要があります。
       * `read:attack_protection`
       * `update:attack_protection`
           <Warning>
             デバイスの記憶期間を Okta の標準推奨設定より長く変更したことで生じるセキュリティ体制の低下については、Auth0 のお客様が責任を負います。
           </Warning>
  </Tab>
</Tabs>

<div id="enable-adaptive-mfa-risk-assessment">
  ## Adaptive MFA リスク評価を有効にする
</div>

Adaptive MFA を有効にする準備がまだできていなくても、ログイン動作の分析に向けた学習を開始したい場合は、Adaptive MFA リスク評価だけを個別に有効化できます。

1. [Dashboard > Security > Multi-factor Auth](https://manage.auth0.com/#/security/mfa) に移動します。
2. **Define policies** セクションを探します。
3. **MFA Risk Assessors** で、**Enable Adaptive MFA Risk Assessment** を選択します。
4. **Save** を選択します。

<div id="customize-adaptive-mfa">
  ## Adaptive MFA をカスタマイズする
</div>

Adaptive MFA の動作は、セキュリティを確保しながら、ユーザーに最適な体験を提供できるようカスタマイズできます。詳しくは、[Adaptive MFA をカスタマイズする](/ja/docs/secure/multi-factor-authentication/adaptive-mfa/customize-adaptive-mfa)を参照してください。

<Callout icon="file-lines" color="#0EA5E9" iconType="regular">
  MFA をトリガーする Actions は、Adaptive MFA の既定の動作より優先されます。
</Callout>

<div id="limitations">
  ## 制限事項
</div>

テナントログの評価情報は、インタラクティブなフローでのみ利用できます。Auth0 では、Adaptive MFA が有効になっていない <Tooltip tip="リソース所有者: 保護されたリソースへのアクセスを許可できるエンティティ（ユーザーやアプリケーションなど）。" cta="用語集を表示" href="/ja/docs/glossary?term=Resource+Owner">リソース所有者</Tooltip> パスワードグラント (ROPG) フローの評価情報の記録はサポートされていません。認証フローの制限事項の詳細については、[Adaptive MFA](/ja/docs/secure/multi-factor-authentication/adaptive-mfa) を参照してください。

<div id="learn-more">
  ## 詳細
</div>

* [Adaptive MFA をカスタマイズする](/ja/docs/secure/multi-factor-authentication/adaptive-mfa/customize-adaptive-mfa)
* [Adaptive MFA のログイベント](/ja/docs/secure/multi-factor-authentication/adaptive-mfa/adaptive-mfa-log-events)
* [多要素認証の認証要素](/ja/docs/secure/multi-factor-authentication/multi-factor-authentication-factors)
