Use when
- A sign-in, new device, risk signal, or sensitive action requires proof beyond the primary credential.
- The account has enrolled second factors, recovery codes, or approved support recovery routes.
- The product can enforce the challenge server-side and return users to the original destination after success.