Login.gov
Product • UX Research • Content Design
Following updates to the design of the authentication selection screen, Team Katherine's next task was to enable and encourage users to select multiple authentication methods when creating an account.
In November 2021, Login.gov only let users to set up only one Multi-Factor Authentication (MFA) method from the MFA Selection screen when first creating an account.
Since the current functionality limits users to only setting up one authentication method at account creation, many users don't realize they can add multiple MFA methods from their account page.
Having only one MFA method increases their chances of being locked out and having to delete their account before creating a new one.
We looked to determine if enabling and encouraging users to create 2 MFA methods when first creating an account would:
The research questions we'd like to answer:
The team conducted 12 unmoderated usability tests via UserTesting.com.
We used a developer sandbox site instead of a prototype to get a better understanding of how people would actually move through the account creation and MFA selection process.
Our first move was to switch the radio button to a checkbox. This minor change subtly indicates to users they can select more than one MFA method tile.
We then added "We recommend you select at least (2) two different options in case you lose one of your methods."
In order to capture users who only selected one MFA method, we decided to add an interstitial "upsell" page after a user successfully sets up their first authentication method.
We explain to them that adding another authentication method would prevent them from being locked out from their account in case they lose one of their methods.
The video below illustrates the interstitial upsell screen popping up if a user only selects one MFA method. The primary call to action "Add another method" takes the user back to the authentication selection page to add another method.
All participants chose Phone/SMS as an MFA method. Of those participants:
10 of 12 participants set up Phone/SMS as their first, primary MFA method.5 of 12 participants selected only 1 MFA method on the first selection screen. Of those users:
We found that a majority of the participants who read the text "We recommend you select two (2) MFA methods..." ended up selecting at least 2 MFA methods even if they weren't sucessful in setting them up. The team felt these designs could be a good start to increasing multiple MFA adoption.
Login.gov released the MFA multi-select feature on July 14 2022. Before the release only 3.6% of new users had more than one MFA in June 2022
By November 2022 34.5% of new users had two or more MFAs at account creation, marking a 30.9% increase in users adding an additional MFA method, making it less likely for users to get locked out of their accounts.
Following the success of this work additional efforts included notifying existing users that they should add another authentication method after signing in. We also created an email to remind existing users that they should add an additional MFA method if they only had one.
© Mostyn Griffith 2022