Push Notification
Users receive an approval request on the 1Kosmos mobile app. From v2.0.4.0, a Number Challenge option is available to protect against push bombing attacks.

Admin Setup
Configure the Authentication Journey
In AdminX, navigate to Applications > Windows MFA > Adaptive Auth Journeys.
Create a new journey or edit an existing one.
Under Authentication Method, select either:
Push Notification - push-only, no password required.
Password & Push Notification - password entered first, then push sent.
Assign the journey to the target user group or machine policy.
Save and publish the journey.
Enable Number Challenge
In AdminX, navigate to Authentication > Passwordless Login > Passwordless Login using 1Kosmos App.
Toggle Enable number challenge on all push notification requests to ON.
Save the settings.
When enabled, all push notifications sent through any journey configured with Push Notification will include a number challenge.
User Guide
Standard Push Notification Login
At the Windows login screen, click the 1Kosmos tile.
If using the Other User tile, enter your username first.
Select Push Notification from the available authentication options.
A push notification is sent to your enrolled 1Kosmos mobile app.
Open the notification and tap Yes, it's me.
The Windows session unlocks and you are logged in.
Push Notification with Number Challenge
At the Windows login screen, click the 1Kosmos tile.
If using the Other User tile, enter your username first.
Select Push Notification from the available authentication options.
A number is displayed on the Windows login screen.
A push notification is sent to your enrolled 1Kosmos mobile app showing multiple numbers.
In the app, tap the number that matches the number shown on the Windows screen.
If the correct number is selected, the Windows session unlocks and you are logged in.
If you tap the wrong number, the authentication attempt is immediately cancelled. You must return to the Windows login screen and initiate a new login attempt. Repeated wrong selections may indicate a push bombing attack — do not approve any push you did not personally initiate.
Behavior Comparison
Interface on Windows login screen
No number displayed
A number is shown on screen
Interface on mobile app
"Yes, it's me" consent screen
Number selection screen with multiple options
Required user action
Tap Yes, it's me
Tap the number matching the Windows screen
Protection against push bombing
Not provided
Active - wrong number cancels auth immediately
Troubleshooting
Push notification not received
Mobile app not enrolled or disconnected; no device internet; OS notifications blocked
Verify mobile app is enrolled and connected; check device internet and notification permissions; ask user to open the app manually and check pending requests
Push notification expired
User did not respond within the timeout window
Initiate a new login attempt from the Windows login screen
Wrong number selected (Number Challenge)
User tapped incorrect number
Authentication is automatically cancelled; initiate a new login attempt; if recurring, verify no push bombing attempt is in progress
User tapped Cancel
User dismissed the notification intentionally or accidentally
Initiate a new login attempt; if recurring, check for unsolicited push notifications and report as a potential push bombing incident
Push received but app shows error
App version outdated; tenant connectivity issue
Update the 1Kosmos mobile app; verify tenant URL and connectivity from the mobile device
Last updated
Was this helpful?

