Setting Up Multi-Factor Authentication (MFA)
Overview
Multi-Factor Authentication adds an extra layer of security to your account by requiring a verification code from your phone in addition to your password.
Why Use MFA?
- Enhanced Security: Protects against password theft
- Compliance: Meets security requirements
- Account Protection: Prevents unauthorized access
- Required: Some organizations mandate MFA
Supported MFA Methods
- TOTP (Time-based One-Time Password): Authenticator apps like Google Authenticator, Authy, Microsoft Authenticator
- Backup Codes: Emergency access codes
Setting Up MFA
Step 1: Access MFA Settings
- Log in to SSO Portal
- Click your name in top-right corner
- Select Profile
- Navigate to Security Settings section
Step 2: Enable MFA
- Under "Multi-Factor Authentication", click Setup MFA
- Choose your MFA provider (usually "Authenticator App")
Step 3: Scan QR Code
-
Open your authenticator app on your phone:
- Google Authenticator (iOS/Android)
- Authy (iOS/Android)
- Microsoft Authenticator (iOS/Android)
- 1Password (iOS/Android)
-
Choose "Add Account" or "Scan QR Code"
-
Scan the QR code displayed on screen
Can't scan QR code? Click "Enter key manually" and type the secret key into your authenticator app.
Step 4: Verify Setup
- Enter the 6-digit code from your authenticator app
- Click Verify and Enable
- MFA is now active on your account
Step 5: Save Backup Codes
- After enabling MFA, backup codes are generated
- Click Download Backup Codes or Print Backup Codes
- Store these codes in a secure location
Important: Backup codes can only be used once. Keep them safe!
Using MFA to Log In
Standard Login Flow
- Enter tenant, email, and password
- Click Sign In
- MFA verification screen appears
- Open your authenticator app
- Enter the 6-digit code
- Click Verify
- You're logged in!
Using Backup Codes
If you don't have access to your authenticator:
- On the MFA verification screen, click Use backup code
- Enter one of your backup codes
- Click Verify
- Important: Each backup code works only once
Trust This Device (Optional)
Some organizations allow you to trust devices:
- Check "Trust this device for 30 days"
- You won't need MFA on this device for 30 days
- Still required on new devices/browsers
Managing MFA
Regenerate Backup Codes
If you've used some backup codes:
- Go to Profile > Security Settings
- Under "Backup Codes", click Regenerate Backup Codes
- Old codes are invalidated
- Download new codes
Disable MFA
Warning: Only disable MFA if absolutely necessary
- Go to Profile > Security Settings
- Click Disable MFA
- Confirm by entering a verification code
- MFA is now disabled
Reset MFA (Lost Phone)
If you lost access to your authenticator:
Option 1: Use Backup Code
- Use one of your backup codes to log in
- Immediately disable and re-enable MFA
Option 2: Contact Administrator
- Contact your tenant administrator
- They can reset MFA on your account
- You'll need to set it up again
Administrator: Managing User MFA
Require MFA for All Users
- Admin > Settings
- Enable Require MFA for all users
- Users will be prompted to set up MFA on next login
View MFA Status
- Admin > Access
- View "MFA Status" column
- See who has MFA enabled
Reset User's MFA
- Admin > Access
- Find the user
- Click Reset MFA
- User must set up MFA again on next login
Troubleshooting
Code Not Working
- Check time sync: Authenticator apps require accurate device time
- Go to phone Settings > Date & Time
- Enable "Automatic date & time"
- Wait for new code: Codes change every 30 seconds
- Try backup code: Use backup code if authenticator fails
Lost Authenticator App
- Use a backup code to log in
- Go to Profile and disable MFA
- Re-enable MFA with new authenticator
- Save new backup codes
Backup Codes Not Working
- Ensure you're entering the code exactly (no spaces)
- Remember: each code works only once
- Contact administrator if all codes used
MFA Required But Not Set Up
If organization requires MFA:
- You'll be redirected to MFA setup on login
- Follow setup steps above
- Cannot skip if required by policy
Best Practices
- Enable MFA on all accounts
- Store backup codes securely (password manager, safe)
- Don't share verification codes
- Use different authenticator app accounts for different services
- Regenerate backup codes periodically
- Enable MFA on your authenticator app account itself
- Test backup codes before storing
Security Tips
- Never share your authenticator secret key
- Don't screenshot QR codes
- Be cautious of phishing attempts asking for codes
- Report suspicious login attempts
- Keep your authenticator app updated
- Use biometric lock on your phone
Support
Need help with MFA?
- Contact your administrator for account resets
- Check your organization's security policy
- Review audit logs for failed MFA attempts