Authentication Methods

How users prove who they are when signing in to Cloud Secure Edge

  • Last validated: Oct 1, 2026

Overview

Once an identity provider supplies the directory of users, these pages cover the methods by which those users authenticate. Each is configured per organization and applies to every user in it.

  • Passwordless Authentication removes the username and password prompt, delegating the sign-in entirely to the identity provider.
  • Certificate-based Multi-Factor Authentication (MFA) uses the device certificate issued by CSE as a second factor, in place of a one-time code.
  • Silent Certificate Authentication authenticates a user session without an interactive prompt.

To connect the directory itself, see Set Up an Identity Provider.

Pages in this section

Passwordless Authentication

Certificate-based Multi-Factor Authentication

Silent Certificate Authentication for User Sessions

Time-based One-Time Passcode for Admins

Was this page helpful?