FAQ about Multifactor Authentication in the CSP

Frequently asked questions about MFA in the CSP

When should you enable or disable MFA?
As a supplier, you can face different scenarios that require you to enable MFA. Take these into account when enabling or disabling MFA:
  • If the customer does not have MFA as a requirement for suppliers, when they enable MFA as a requirement, then:
    • Every supplier for that customer is then required to enable MFA in order to access any of that customer's information through the CSP.
    • Suppliers without MFA receive a message that they must enable MFA in order to transact with the customer. The message contains a link directing the supplier to the page where MFA can be enabled. The supplier requires a phone with SMS texting or an authenticator app to enable this option.
    • The customer’s Coupa Admin can set up an exception in the platform to "Exclude" a specific supplier from the MFA requirement in CSP. This supplier will have access to specific information.
  • If a customer requires the supplier MFA and the supplier does not have MFA enabled, then:
    • The supplier can not see customer data and is instructed to turn on MFA in order to see customer data.
    • When the supplier logs into CSP and navigates to see any customer specific information, they receive a message that they must enable MFA in order to transact with their customer. The message contains a link directing the supplier to the Account Settings page > Security & Multi Factor Authentication tab where MFA can be enabled.
  • If a customer requires the supplier MFA and the supplier has disabled or turned off the MFA option (supplier has transaction history with the customer, but no longer does business with them), then:
    • The supplier can log into the CSP normally, however, in order to view past data or access customer-specific information with that particular customer they must enable MFA.
What is multifactor authentication?

Multi-factor authentication (MFA) is an added layer of security which makes it harder for someone else to get into your CSP account, even if they have your password.

If you try to log in from a device that we don’t recognize, for example a computer from which you have never logged in to the CSP before, we ask you to enter a verification code (the second factor) to make sure it is really you. This verification code is generated by your authenticator app or sent in a text message to your mobile phone.

If someone else is trying to log into your account, they won’t get the code, which could stop them from accessing your account.

For more information, see Manage Multi-Factor Authentication.

Why should I use multifactor authentication?

Securing your transactions is Coupa's top priority. The continuous improvements to the CSP help keep your accounts and data safe. Adding MFA to your account increases its security.

MFA is mandatory with sensitive payment accounts to increase the security of your payment settings in Coupa.

How does multifactor authentication work?

MFA increases security beyond simply having a password. Once MFA is turned on, you can use your Coupa password and a verification code every time you need to change your payment account settings. The verification code is the multi-factor authentication piece. Verification codes can be generated from your authenticator app, which is the preferred option, or sent in a text message to your registered mobile phone.

Which multifactor authentication method is recommended?

The recommended MFA option is using a Passkey, or MFA through an authenticator app, for example, Google Authenticator, Twilio Authy, or Microsoft Authenticator Authy, is the preferred method. You can download one of these apps for free from the Apple App Store or Google Play.

Is multifactor authentication mandatory?

MFA is mandatory with CSP payment accounts, and certain actions as account administrator. MFA is not mandatory with the other features of the CSP.

Which payment account updates require multifactor authentication?

Sensitive account updates, namely changes to your legal entity, remit-to, and bank account information require MFA.