AuthHub - CloudHealth SSO users prompted for Broadcom MFA due to multiple Site IDs or Incognito Mode
search cancel

AuthHub - CloudHealth SSO users prompted for Broadcom MFA due to multiple Site IDs or Incognito Mode

book

Article ID: 448121

calendar_today

Updated On:

Products

CloudHealth

Issue/Introduction

Users accessing CloudHealth via corporate Single Sign-On (SSO) may encounter an unexpected Broadcom Login Security Code (MFA) prompt under the following conditions:

  • Incognito/Private Mode: The browser is unable to retrieve the required AuthHub security SSO cookie.
  • Enterprise Profile: When a Broadcom profile is associated with two or more Support Site IDs.

Environment

  • Product: CloudHealth by Broadcom

Cause

This behavior is driven by how AuthHub handles identity elevation:

  1. Identity Elevation: When a Broadcom profile is associated with two or more Support Site IDs, the user is no longer just a "Federated" SSO User. They are classified as a multi-site Enterprise User, which could mandate a MFA for login attempts if AuthHub cannot find the SSO token.
  2. Session Persistence: AuthHub uses a security cookie to 'remember' a device. 

Resolution

Option 1: Use Browser Profiles (Recommended for Multi-Window Reporting)

To view multiple CloudHealth reports (e.g., AWS vs. Azure) simultaneously without triggering MFA in Incognito mode:

  • Create separate profiles: In Chrome, Edge, or Firefox, create a new browser profile for each reporting view.
  • Persistence: Unlike Incognito mode, separate profiles persist their own cookies. This allows you to stay signed in via SSO in both windows without repeated MFA prompts.

Option 2: Consolidation of Site IDs

If the user does not require access to secondary Site IDs, removing the additional associations from their Broadcom profile can stop the mandatory MFA Broadcom trigger.

  • Process: Contact Broadcom's Global Customer Assistance to review the user's profile and remove unnecessary Site ID associations

Option 3: The "Not You?" Workaround

If the prompt appears in a standard window due to a cached session from another Broadcom product:

  1. Click the "Not [Your Email]?" link on the login page to clear the saved state.
  2. Navigate back to .
  3. Enter your email to re-initiate the direct redirect to your corporate IDP.

Additional Information

To confirm if your profile has been elevated due to multiple Site IDs:

  1. Log in to the .
  2. Click the profile drop-down menu in the upper-right corner and select My Profile.
  3. Navigate to the My Entitlements tab.
  4. Review the list of Site IDs. If more than one Site ID is listed, the account is no longer considered a standard Federated user and will require MFA.