CloudSketch AI Logo
FeaturesTemplatesPricingEnterpriseAboutContactLog in
πŸŒ™β˜€οΈ
Log inStart free
Home/Templates/Cybersecurity

πŸ” Cybersecurity Β· Sequence

Multi-Factor Authentication Login Sequence

How a login with MFA works: password check, risk evaluation, a push or TOTP challenge and session issue.

More Cybersecurity templates

Drawing diagram…

What this diagram shows

  • Low-risk logins from known devices can skip the second factor
  • Push approval shows the location to stop MFA fatigue attacks
  • Every login attempt is logged for the SOC

Prompt used

MFA login sequence: the user enters username and password in the app. The identity provider checks the password, then a risk engine scores the login (device, IP reputation, location, impossible travel). For higher risk it sends a push notification with number matching to the authenticator app (or asks for a TOTP code). After approval, the identity provider issues tokens and logs the event to the SIEM.

Mermaid code
sequenceDiagram
  actor U as User
  participant APP as Application
  participant IDP as Identity Provider
  participant RISK as Risk Engine
  participant AUTH as Authenticator App
  participant SIEM as SIEM
  U->>APP: Username and password
  APP->>IDP: Authenticate
  IDP->>IDP: Verify password hash
  IDP->>RISK: Score device, IP, location
  RISK-->>IDP: Medium risk
  IDP->>AUTH: Push with number match
  U->>AUTH: Approve with matching number
  AUTH-->>IDP: Approved
  IDP-->>APP: ID and access tokens
  IDP-)SIEM: Login event

Related templates

C4 ArchitectureProCybersecurity

Zero Trust Architecture

A zero trust access model: every request to an internal app is checked for user identity, device health and policy, whether it comes from the office or home.

FlowchartCybersecurity

Security Incident Response Workflow

A security incident response process based on the NIST lifecycle: detect, triage, contain, eradicate, recover and learn.

Data FlowCybersecurity

SIEM Log Pipeline

How security logs from across an organisation reach the SIEM: collection, parsing, enrichment, detection rules and alerts for the SOC.

SequenceCybersecurity

SAML Single Sign-On Login

How SAML single sign-on works when an employee opens a SaaS app: redirect to the company identity provider, MFA and a signed assertion.

NetworkCybersecurity

DMZ Network Architecture

A classic secure network layout: internet-facing services in a DMZ between two firewalls, with internal systems and databases never exposed directly.

MindmapCybersecurity

Threat Model Mindmap (STRIDE)

A STRIDE threat model for a web application, listing example threats in each category with the main mitigations.