# Step-Up authentication combined with RequiredAction maxAuthAge

**URL:** <https://forum.keycloak.org/t/step-up-authentication-combined-with-requiredaction-maxauthage/24404>\
**Category:** Miscellanaeous\
**Created:** [February 5, 2024, 11:27am UTC](https://forum.keycloak.org/t/step-up-authentication-combined-with-requiredaction-maxauthage/24404 "2024-02-05T11:27:24Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![dominiktopp](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/dominiktopp/32/9104_2.png) [@dominiktopp](https://forum.keycloak.org/u/dominiktopp)\
**Post date:** [February 5, 2024, 11:27am UTC](https://forum.keycloak.org/t/step-up-authentication-combined-with-requiredaction-maxauthage/24404/1 "2024-02-05T11:27:24Z")

</div>

Hi,

now that we have implemented step-up authentication (thanks for your help in [Step-up Authentication max age and token lifespan](https://forum.keycloak.org/t/step-up-authentication-max-age-and-token-lifespan/24232)), we have a new problem with reauthentication for required actions.

Before step-up authentication has been implemented:  
We extended UpdatePassword exactly like dasniko did in his video [https://www.youtube.com/watch?v=0JcYlNUiBsA](https://www.youtube.com/watch?v=0JcYlNUiBsA). With the default browser flow from Keycloak, the user then has to reauthenticate using his password and OTP (if configured).

With step-up authentication we changed the browser flow: OTP is only checked if specific LoA (lets say 2) is required. Now when the user wants to update his password, the ConditionalLoaAuthenticator for LoA 2 skips the OTP.

How can we tell Keycloak to also ask for OTP if the user wants to update his password (or invokes another required action with maxAuthAge=0)?

Thanks 🙂
