Step-up verification
Ask a user for a second proof after their password: a passkey, or a code from an authenticator app. You can require it before a sensitive operation, or on every sign-in to an app.
A second step, after a password
A passkey here is a second factor and never a way to sign in on its own: the sign-in page offers no passkey option. A security key can be used in its place. Stepping up re-checks the password first, so only a user who has a password can enrol a factor or prove one.
Before a sensitive operation
An operation can require a second factor. You set the requirement with foir operations update and its --second-factor flag, and it reaches production at the next release. A run whose session has not proven a factor is refused with FAILED_PRECONDITION and a message you can word yourself. An operation that carries the requirement cannot be started by a hook or a schedule.
On every sign-in to an app
Each sign-in app has a Require MFA switch in the console. With it on, a password sign-in on the hosted page completes only after the user proves a factor. A user with none enrols during that sign-in, with a passkey or by scanning a QR code into an authenticator app.
The switch also shuts out anyone without a password. Users who sign in with an emailed code or through an identity provider cannot sign in to that app at all.
Stepping up without signing out
A signed-in user can enrol or step up in the middle of a session. They re-enter their password and prove the factor, and the proof is added to the session they already hold. This needs a session on a verified custom login domain. An app on the token flow has no such session, and its users get a second factor by signing in again through an app that requires one.
Read the detail
Step-up has no documentation page of its own, and the operation endpoint guide covers only the requirement you set on an operation.