---
locale: "en"
updated_at: "2025-10-27T13:29:46.630Z"
canonical: "https://www.isdecisions.com/en/userlock/docs/guides/end-users-mfa-enrollment/userlock-push-app"
---

# Enroll users with the UserLock Push application

Enroll the UserLock Push App to receive MFA notifications.

## Introduction

**UserLock Push** is a feature of UserLock that uses the [UserLock Push mobile app](/userlock/docs/reference/userlock-push-application) (available on iOS and Android) to deliver secure push notifications for multi-factor authentication (MFA).

Users can approve or deny login requests in real time from their phone, or use the app’s built-in **TOTP codes** when offline.

Push notifications can be used with all connection types protected by UserLock MFA: 

- Local and RDP sessions,
- RD Gateway, RDWeb,
- RemoteApp,
- VPN,
- IIS,
- and SaaS applications.

The mobile app can also manage **standard TOTP accounts** (for example Gmail, GitHub, or Microsoft 365), allowing users to centralize all their authentication codes.

> **Note**
>
> 🚩 **Before following this guide:**
> We recommend reading [How to implement MFA](/userlock/docs/guides/mfa-implementation/how-to-implement-mfa) for general recommendations, communication tips, and preparation steps to ensure a smooth rollout.

> **Note**
>
> You can find detailed information on using the app, managing accounts, and reviewing push requests in the [UserLock Push App Reference](/userlock/docs/reference/userlock-push-app).

## Requirements

- **UserLock Server** must have an Internet access with **outbound HTTPS traffic (TCP 443)** allowed to the following endpoints:
  - `push.isdecisions.com`
  - `idp.isdecisions.com`
- [UserLock Anywhere](/userlock/docs/reference/server-settings/general#userlock-anywhere) must be configured (to reach agents outside the network).
- The UserLock **Desktop Agent** must be installed on the workstation.
- The workstation must have Internet access when outside the corporate network.
- **Smartphone**:
  - iOS 13.0 or later, or Android 5.0 or later
  - **UserLock Push** app installed from the App Store or Google Play.

> **Note**
>
> If the user is already enrolled with another MFA method and wants to switch to Push, an administrator must **reset the MFA key** before re-enrollment.

## Step 1. Enable Push notifications in UserLock

Before enrolling users, an administrator must enable the **Push notifications** method in the UserLock console.

1. Open the **UserLock Console**.
2. Go to ⚙ **Settings ▸ MFA**.
3. Under **MFA methods**, enable **Push notifications**.
4. Save the configuration.

Once Push is activated as an MFA method, it becomes available for use in user enrollments.

## Step 2. Enable MFA for the user

Before enrolling, make sure that **MFA is enabled** for the user account in UserLock.

> **Note**
>
> - See [Access policy management](/userlock/docs/reference/access-policies/access-policy-management) to learn how to apply an access policy in UserLock.
> - See [MFA policy reference](/userlock/docs/reference/access-policies/mfa) for details on MFA policy rules and options.

## Step 3. Enroll the UserLock Push app

1. On your smartphone, open the **App Store** or **Google Play** and search for **UserLock**.
2. Download and install [UserLock Push](/userlock/docs/reference/userlock-push-app)
3. On your computer, at your next login, select **Push notifications** card when prompted for MFA enrollment.
  ![](https://a.storyblok.com/f/122374/495x391/848f90710b/1-mfa.png)
4. Scan the **QR code** displayed on your screen using the **UserLock Push** app
  ![](https://a.storyblok.com/f/122374/751x559/b6a20995e2/mfa-enrollment-push-application.png)
5. Tap **Continue** to complete enrollment.

The UserLock Push app is now configured as your **primary MFA method**.
If push notifications are unavailable, use the **TOTP code** displayed in the app.

> **Note**
>
> If your administrator also requires [another MFA method](/userlock/docs/reference/server-settings/mfa-settings#mfa-methods), you may be prompted to enroll it. If you cannot complete that enrollment, cancel and contact your administrator. Adding another method later **requires restarting the MFA setup**.

## Step 4. Authenticate

Once enrolled, MFA with UserLock Push will trigger automatically during login.

1. Enter your Windows credentials.
  ![](https://a.storyblok.com/f/122374/640x639/89d6c7d38a/cred_prov_push_eng.png)
2. A **push notification** is sent to your smartphone.
3. **Approve** or **refuse** the login request directly from the notification.
  - If you’re offline or the push fails, open the app and enter the **TOTP code** instead with the **Enter code** button.

> **⚠️ If you receive a request you didn’t initiate:**
>
> Refuse it, change your password immediately, and contact your IT Help Desk.
