Is there anyway we can add a link to the suspicious activity email that allows the user to click on it to setup MFA?

So for example we have a message worried about your account you can make it more secure by setting up an additional factor click here to setup.

Then is there a way to only trigger MFA for users that have it setup, rather than all users of the app.


After initial factors / Authenticators (OIE) are enrolled to meet the Org requirements a user will no longer be given the option during login.
Typically this could be done via the user dashboard under settings, or if you have some sort of Admin App that can make management API calls and enroll the user into additional Factors/Authenticators.

In the email template a link could be set to this Admin app.

