Strong Customer Authentication and the Trusted Beneficiary List

The Hungarian National Bank has recently noticed a fraudulent practice in online payments. An online or mobile app session can involve multiple actions, but does each require strong client authentication? When logging into the online interface, initiating the payment and compiling the trusted beneficiary list? Or can these go within the same session with the same authentication element? MNB turned to EBA for an answer.