Multi-factor authentication setup blocks ECN approval on mobile devices

We recently enabled multi-factor authentication across our Teamcenter 13.1 environment to improve security compliance. Everything works fine on desktop browsers, but our engineering team is reporting that they cannot approve ECNs from the mobile app anymore.

The authentication flow completes successfully - users receive the MFA code via SMS, enter it correctly, and get logged into the mobile app. However, when they try to approve an ECN from their notification queue, the app shows a spinning loader for about 30 seconds and then displays “Authentication failed. Please try again.”

We’re using the standard Teamcenter mobile app (version 13.1.2) and have tested with both SMS and authenticator app methods for MFA. The issue occurs consistently across iOS and Android devices, even when users are on corporate WiFi with stable network connectivity. Desktop approvals work perfectly fine with MFA enabled.

Has anyone encountered this specific issue with MFA blocking mobile ECN approvals? Could this be related to how the mobile app handles session tokens after MFA validation?

I struggled with this for weeks before finding the solution. The issue is that TC 13.1’s mobile app has a compatibility gap with MFA when performing workflow actions like ECN approvals. Here’s what you need to address:

MFA Method Compatibility Issue: The mobile app version 13.1.2 has a known bug where it doesn’t properly refresh the MFA authentication token during approval workflows. After the initial MFA login succeeds, the app caches the primary authentication token but fails to include the MFA validation token in subsequent API calls for approval actions. This is why desktop works (browser handles token refresh automatically) but mobile fails.

Solution - Upgrade and Configure: First, upgrade to mobile app version 13.1.4 or later. This version includes the critical fix for MFA token handling during workflow operations. If you’re using SMS-based MFA, the token validity window needs to be extended in your MFA provider settings - set it to at least 10 minutes instead of the default 5 minutes to accommodate the approval workflow’s multiple API calls.

Mobile App Version Compatibility: Verify your mobile app backend configuration. In the MobileServerConfig.xml file on your Teamcenter server, ensure these settings are present:

<mfa-token-refresh enabled="true"/>
<session-extension-for-workflows value="600"/>
<approval-api-timeout value="45000"/>

The session-extension-for-workflows parameter is crucial - it extends the authentication session specifically for approval workflows to prevent timeout during the multi-step approval process.

Network Connectivity Requirements: The mobile app needs consistent network connectivity throughout the approval process because it makes 3-4 sequential API calls (validate approval authority, check ECN status, submit approval, trigger notifications). If users switch between WiFi and cellular during this sequence, the MFA token validation can fail. Configure your mobile device management to prefer WiFi for the Teamcenter app, or ensure your MFA provider supports token validation across network transitions.

Additional Configuration: In your MFA provider settings, whitelist these specific mobile API endpoints that handle approvals:

  • `/tc/mobile/api/workflow/approve
  • `/tc/mobile/api/notification/action
  • `/tc/mobile/api/ecn/approve Also check your firewall logs - some corporate firewalls treat rapid sequential API calls from mobile devices as suspicious activity and throttle them, causing the 30-second timeout you’re seeing.

After implementing these changes, have users completely log out and back in to the mobile app to refresh all cached tokens. The approval workflow should then work seamlessly with MFA enabled.


This draft is based on general Teamcenter knowledge. It has not been verified against your specific version and environment. Practitioners: verify the steps and share your experience below.

I’ve seen similar authentication issues with mobile apps after MFA rollout. In our case, the problem was that the mobile app session timeout was shorter than the MFA token validity period. Check your wt.auth.session.timeout settings specifically for mobile clients versus desktop sessions.

This sounds like a known compatibility issue between certain MFA providers and the mobile app’s REST API authentication flow. The mobile app uses a different authentication mechanism than the web client, and some MFA methods don’t properly pass the secondary authentication token through the mobile API gateway. We had to configure our MFA provider to whitelist the mobile app’s API endpoints and extend the token validation window. Also verify that your firewall isn’t blocking the mobile app’s specific authentication ports (usually different from standard HTTPS). The 30-second timeout you’re seeing is typically the mobile app waiting for a response that never arrives due to network-level blocking.

Have you checked the mobile app version compatibility matrix? TC 13.1 had several mobile app updates specifically addressing MFA integration. Version 13.1.2 should work, but there were critical fixes in 13.1.3 patch that resolved token refresh issues during approval workflows.

We experienced this exact scenario three months ago. The root cause was that our MFA solution was validating the initial login but not properly extending authentication for subsequent API calls made by the mobile app during the approval process. Each approval action triggers multiple backend API calls, and if the MFA token isn’t being passed correctly in the request headers for these subsequent calls, they fail authentication. Check your method server logs during a failed mobile approval - you’ll likely see authentication exceptions for the approval service calls even though the initial login succeeded. We also noticed that network connectivity matters more than you’d think - mobile devices switching between WiFi and cellular during the approval process would definitely cause token validation failures.

Look into your SSO configuration if you’re using it alongside MFA. The mobile app handles SSO tokens differently than web browsers, and there can be conflicts in how the authentication chain processes both SSO and MFA credentials for approval workflows specifically.

Confirmed this resolves the issue — after TC 13.1.2 mobile app update, MFA validation tokens now persist correctly through ECN approval workflow API calls.

Version 13.1.2 should work, but there were critical fixes in 13.1.3 patch that resolved token refresh issues during approval workflows.