Enabling MFA in your CSP account

Configure your preferred Multifactor authentication (MFA) method in the CSP.

Multifactor authentication (MFA) is the recommended security option to protect accounts. It requires the user to provide two or more verification factors to gain access to the Coupa Supplier Portal (CSP).

For more information see Manage Multifactor Authentication in the CSP.

To enable any MFA method in the Coupa Supplier Portal (CSP), follow the steps below:

  1. Go to the Account Settings page.
    You can reach this page by selecting your profile name on the top-right corner of the window, and selecting the Account Settings option.
    Figure 1. How to access the Account Settings page
  2. Select the Security & Multi Factor Authentication tab.
    The Security & Multi Factor Authentication can be found on the left navigation bar.
    Figure 2. Security & Multi-Factor Authentication page
    The "My Account Security & Multi-Factor Authentication" page in the Coupa Supplier Portal . The left sidebar highlights the active "Security & Multi-Factor Authentication" link in orange. The main pane displays the "Multi-Factor Authentication" configuration, starting with two radio buttons where "For Payment Changes (Required for changing Legal Entity or Remit-to)" is selected. Below this, three option cards are listed: "Via Authenticator App", "Via Passkey" (marked as default with a blue checkmark and a selected radio button), and "By Alternative Email". At the bottom of the page, two buttons read "Show Recovery Codes" and "Regenerate Recovery Codes".
  3. Select when you want the CSP to enforce MFA.
    Select one of the options on screen:
    Figure 3. Select what sections of the CSP ask for MFA
    A focused, close-up view of the "My Account Security & Multi-Factor Authentication" header area. The left sidebar has "Security & Multi-Factor Authentication" selected in orange. The main content area shows the "Multi-Factor Authentication" header and two preference radio buttons. The first option, "For Payment Changes (Required for changing Legal Entity or Remit-to)," is checked, while "For Both Account Access (Login) and Payment Changes" is unchecked.
    • For Payment Changes (Required for Changing Legal Entity or Remit-To):

      MFA wil be required when creating or editing legal entities, remit-to, and bank account information.

    • Both Account Access (Login) and Payment Changes:

      MFA will be required when logging in to the CSP.

      You don't have to reauthenticate when working with financial data because you already authenticated when logging in.

  4. Select the MFA method depending on how you want to receive the verification codes.
    Select one of the options on screen:
    Figure 4. MFA options on the CSP
    An close-up view showing the three Multi-Factor Authentication option cards. The top card, "Via Authenticator App," is active, featuring a blue checkmark badge and has a selected "Default" radio button, and a "Change Authentication App" link. The middle card is "Via Passkey," displaying an unselected "Default" radio button. The bottom card is "Via Alternative Email," also displaying an unselected "Default" radio button . Each card includes a brief description explaining how the respective method is used to secure the account with standard mobile apps, browser-stored passkeys, or backup emails.
    1. Using an Authenticator App (available from the app store) on your mobile phone to generate a code. This is the recommended option.
    2. Using a passkey to sign in.
    3. Using email to receive a code.
  5. Select

When you enable MFA, you get an email notification of the change.

Depending on your selected preferred MFA method, you will need to follow additional steps. See the additional information links for more.

After configuring MFA for the first time, you can log in to the CSP using the same passkey, and select the option to remember your browser to avoid having to enter it unnecessarily.

For more information see Sign in to the CSP using MFA.