Unregistered Multi-factor Authentication (umfa) is about being possible to require Unregistered SMTP OTP or Unregistered SMS OTP as the second factor authentication method for unregistered users returned from a SAML or an OpenID Connect method.
Configuration
Create the first factor method
SAML
OpenID Connect
Create the second factor method
Unregistered SMTP OTP
Unregistered SMS OTP
While not required, it’s useful to verify at this point that both work individually without the umfa configuration.
Set following configuration string for the second factor method
mfa true