Multifactor authentication
-
AppColl should support (and encourage) multifactor authentication. Preferably, you would allow the user to select multiple methods from a list of methods, such as email, SMS message, push notification, TOTP, and digital certificate. That way, if for some reason one method isn't working at login, an alternate method could be used.