Auth0 Exposes Tenant Name During MFA With Custom Domains

Overview

While the Custom Domain feature replaces the canonical domain, Auth0 still exposes the tenant name in the URL during a Multi-Factor Authentication (MFA) challenge. This behavior is by design, and there is no workaround to prevent the tenant name from appearing in the URL. Network administrators may notice this behavior when strictly controlling the domain allowlist.

Applies To

  • Auth0
  • Custom Domains
  • Multi-Factor Authentication (MFA)

Solution

Why does Auth0 expose the tenant name during an MFA challenge?

Review the following information regarding tenant name exposure during an MFA challenge:

  • While the Custom Domain feature replaces the canonical domain, Auth0 still connects the URL using the tenant name, such as https://<tenant>.guardian.[au|ca|eu|jp|uk].auth0.com, during an MFA challenge.
  • Network administrators may notice this behavior when strictly controlling the domain allowlist.
  • This behavior is by design, and there is no workaround available.

 

Related References

Recommended content

No recommended content found...