JumpCloud MFA works by prompting users for a second factor—such as a time-based one-time password (TOTP), push notification via the JumpCloud Protect app, or a hardware token—after entering their primary credentials.