---
locale: "en"
updated_at: "2025-11-24T11:39:16.974Z"
canonical: "https://www.isdecisions.com/en/userlock/docs/reference/modules/userlock-push-application"
---

# UserLock Push Application

Requirements, features and settings of the Push App.

## Overview

The **UserLock Push App** is the mobile application which allows users to receive **secure MFA push notifications** to approve or deny login requests directly from their smartphone, providing fast, frictionless authentication.

When network access is unavailable, the app also generates offline **TOTP codes**.
In addition, it can store third-party TOTP accounts (e.g., Gmail, GitHub, Microsoft 365) to centralize all MFA credentials in one place.

#### Key advantages:

- **One-tap authentication:** Approve or deny sign-ins instantly from your smartphone.
- **Context-aware security:** See login location, device, and timestamp before approving.
- **Offline access:** Use a **TOTP code** if you’re not connected to the Internet.
- **Unified app:** Manage all your UserLock and third-party accounts in one place.
- **Remote ready:** Works seamlessly with **UserLock Anywhere** for users outside the corporate network.

#### Availability

The UserLock Push App is available for:

- iOS 15.1+
- Android 7.0+

|  |  |
| --- | --- |
| ![](https://a.storyblok.com/f/122374/159x48/1c42af4d3a/get-it-on-google-play.png) | ![](https://a.storyblok.com/f/122374/160x47/4427f77ee9/download-app-store.png) |

## Requirements

To use UserLock Push, the following conditions must be met:

- **UserLock Server** must have an Internet access with **outbound HTTPS traffic (TCP 443)** allowed to the following endpoints:
  - `push.isdecisions.com`
  - `idp.isdecisions.com`
- The **Push notifications **methods must be enabled under ⚙ **Settings ▸ MFA ▸ ****[MFA methods](/userlock/docs/reference/server-settings/mfa-settings#mfa-methods)**
- [UserLock Anywhere](/userlock/docs/reference/server-settings/general#userlock-anywhere) must be configured (to reach agents outside the network).
- The UserLock **Desktop Agent** must be installed on the workstations.
- The workstations must have Internet access when outside the corporate network.
- The user’s smartphone must have Internet access to receive push notifications.
- The user must be [enrolled in the Push method](/userlock/docs/guides/end-users-mfa-enrollment/userlock-push-app).

> **Note**
>
> If the user is already enrolled with another MFA method and wants to switch to Push, an administrator must **reset the MFA key** before re-enrollment.

## How it works

When users log in to Windows, **UserLock Push** supports two authentication modes:

- **Push notification (recommended):**
  1. A notification appears on the user’s smartphone.
  2. The user reviews the login details (device, location, time) and taps **Approve** or **Deny**.
  3. The login completes immediately after approval.
  ![](https://a.storyblok.com/f/122374/1179x2556/2c47fef9f6/userlock-push-application-logon-attempt.png)
- **TOTP code (offline mode):**
If the device is offline or push delivery fails, the user can open the app and enter the 6-digit code displayed.
  ![](https://a.storyblok.com/f/122374/1179x2556/63c47ee734/userlock-push-application-account-opened.png)

Each request includes context such as **device name**, **location**, and **timestamp**, helping users confirm authenticity before approval.

> **Note**
>
> ⚠️ **If you receive an unexpected request:**
> Refuse it, change your password, and contact your IT Help Desk immediately.

## Managing accounts

The UserLock Push App can manage both **UserLock** and **third-party TOTP** accounts (e.g., Gmail, Facebook, GitHub).

### Add an account

Tap **+** in the app to scan the QR code provided by the service.
The new account appears in the dashboard.

> **Note**
>
> Always back up recovery codes or keys provided by third-party services.
> IS Decisions cannot recover lost third-party accounts or MFA data.

### Edit or remove an account

Select an account and tap **Modify account** to rename or update it.
To delete it, tap **Delete account** and confirm.

|  |  |
| --- | --- |
| ![](https://a.storyblok.com/f/122374/1179x2556/39d47def2c/userlock-push-application-edit-account.png) | ![](https://a.storyblok.com/f/122374/1179x2556/2dc0ecf543/userlock-push-application-delete-accounts.png) |

> **Note**
>
> Deleting a UserLock MFA account requires a new MFA enrollment before you can log in again.

## Requests history

The **Requests History** feature allows you to review all recent push notifications sent by UserLock.

![](https://a.storyblok.com/f/122374/1179x2556/acb4533036/userlock-push-application-requests-history.png)

Each entry includes:

- **Status:** Approved, refused, or ignored
- **Device name** used during login
- **Location and IP address** of the attempt
- **Date and time** of the event

### 

This feature helps users to:

- Verify legitimate access activity.
- Identify any **suspicious or unauthorized login attempts**.
- Report security issues quickly to their IT administrator.

> **Note**
>
> If you notice a request from an unknown device or location, deny it immediately and alert your IT Help Desk.

## Application settings

Access **Settings **⚙** **to personalize your app experience and enhance security.

![](https://a.storyblok.com/f/122374/1179x2556/cc915b2458/userlock-push-application-settings.png)

- **Use system theme**: Switch between light and dark mode according to your device preferences.
- **Biometric access (Face ID / fingerprint):**
Activate this option to protect access to the app.
You will need to authenticate using Face ID or your fingerprint before viewing your MFA codes or approving requests.
This prevents unauthorized individuals from accessing your codes if your phone is unlocked.
  > **Important**
  >
  > Biometric access secures the **app interface only** — it does **not** approve login requests automatically.
- **Help**: UserLock Help Page
- **Privacy Policy: **View [information](https://www.isdecisions.com/company/privacy-policy/) about data protection and app privacy.
- **Version**: Displays the installed app version.

> **Recommendation**
>
> Keep the app up to date to benefit from the latest features and security improvements.
