> ## Documentation Index
> Fetch the complete documentation index at: https://docs.frankieone.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Multi-factor Authentication

## Introduction

### What's MFA?

Multi-factor authentication (MFA) is an authentication method that requires the user to provide two or more verification factors to gain access to a resource such as an application, online account, or a VPN. MFA is a core component of a strong identity and access management (IAM) policy.

A factor in authentication is a way of confirming your identity when you try to sign in. For example, a password is one kind of factor, it’s a thing you know. The three most common kinds of factors are:

* Something you know - Like a password, or a memorized PIN.
* Something you have - Like a smartphone, or a secure USB key.
* Something you are - Like a fingerprint, or facial recognition.

### Benefits of MFA

Adding MFA to login screens can provide several benefits, such as:

* Reducing fraud and identity theft by making it harder for hackers to access accounts with stolen passwords.
* Increasing customer trust by showing that their data is secure and protected.
* Achieving compliance with regulations and standards that require MFA for certain types of data or transactions.
* Reducing operating costs by minimizing the need for password resets, help desk calls, and breach remediation.
* Streamlining safe mobile transactions by enabling users to authenticate with their smartphones or other devices.
* Preventing password fatigue by allowing users to sign in with fewer passwords or no passwords at all.
* Simplifying the login process by offering users convenient and user-friendly options for authentication

## Enabling multi-factor authentication in the portal

To secure your account with MFA, you can enable the feature from the portal. Once you're logged in, select the **Profile** menu, then **Settings**.

<img src="https://mintcdn.com/frankieone-f5583b1b/7CDIze6_8GRGrpBN/images/v2/portal/8d8fd9c-image.webp?fit=max&auto=format&n=7CDIze6_8GRGrpBN&q=85&s=591f2a1815953c4ffa01a307859092e9" alt="" width="280" height="223" data-path="images/v2/portal/8d8fd9c-image.webp" />

In the **Settings** page, select the **Enable MFA** button to open the **Enable multi-factor authentication** modal.

<img src="https://mintcdn.com/frankieone-f5583b1b/Q0p9n7SnI12Y4IML/images/v2/portal/c309cfc-image.webp?fit=max&auto=format&n=Q0p9n7SnI12Y4IML&q=85&s=745d2d51b381b5396c2d762aa9bd03f8" alt="" width="883" height="568" data-path="images/v2/portal/c309cfc-image.webp" />

Select the additional factor for authenticating your login to your account. Please note that you can only select to receive the security code from an authentication app or in your email and not both.

<Frame caption="Enable multi-factor authentication modal.">
  <img src="https://mintcdn.com/frankieone-f5583b1b/kuSfFEj6euwHKbOF/images/v2/portal/036c57a-MFA2_cr.png?fit=max&auto=format&n=kuSfFEj6euwHKbOF&q=85&s=5882a894e019b51601d9bdda1f8d55f8" alt="Enable multi-factor authentication modal." width="885" height="498" data-path="images/v2/portal/036c57a-MFA2_cr.png" />
</Frame>

### Authentication app

If you selected to use an authentication app for MFA, a QR code or key will be displayed on the **Setting up MFA with an authentication app** modal.

<Frame caption="The Setting up MFA with an authentication app modal.">
  <img src="https://mintcdn.com/frankieone-f5583b1b/aMfFq_kgPrWD4cV3/images/v2/portal/27c3448-MFA3_cr.png?fit=max&auto=format&n=aMfFq_kgPrWD4cV3&q=85&s=9b8a51948bde1ec7b093119fc84aaf47" alt="The Setting up MFA with an authentication app modal." width="935" height="526" data-path="images/v2/portal/27c3448-MFA3_cr.png" />
</Frame>

Scan the QR code using your preferred authentication app, or you can also enter the provided key.

<Frame caption="Sample Authentication app: Google Authenticator.">
  <img src="https://mintcdn.com/frankieone-f5583b1b/7CDIze6_8GRGrpBN/images/v2/portal/84feb84-authentication_app.webp?fit=max&auto=format&n=7CDIze6_8GRGrpBN&q=85&s=4123ee302fd54ad9b7738a5222fec00d" width="300px" data-path="images/v2/portal/84feb84-authentication_app.webp" />
</Frame>

Once the QR code has been accepted and registered on your authentication app, it will generate a 6-digit security authentication code. Copy that code and enter it in the provided field in the **Setting up MFA with an authentication app** modal in the portal.

<Frame caption="Enter the generated code from the authentication app.">
  <img src="https://mintcdn.com/frankieone-f5583b1b/aMfFq_kgPrWD4cV3/images/v2/portal/6f9bd2f-MFA4_cr.png?fit=max&auto=format&n=aMfFq_kgPrWD4cV3&q=85&s=66ec6997e91a719508c64e10d20f07c0" alt="Enter the generated code from the authentication app." width="969" height="545" data-path="images/v2/portal/6f9bd2f-MFA4_cr.png" />
</Frame>

Select **Verify**. A new modal screen will open and provide you with your recovery codes. Make sure to follow the provided instructions and keep these codes safe and secure.

<img src="https://mintcdn.com/frankieone-f5583b1b/kuSfFEj6euwHKbOF/images/v2/portal/0b166a2-MFA5_cr.png?fit=max&auto=format&n=kuSfFEj6euwHKbOF&q=85&s=2a5eed184a44d63b6f5532fdc43d1773" width="966" height="543" data-path="images/v2/portal/0b166a2-MFA5_cr.png" />

<Info>
  Secure your codes

  If you lose access to your authentication app, the recovery codes will be used to authenticate your login. If you lose access to both your authentication app and the recovery apps, you will lose access to your account. If this happens, contact your support team. For users with admin roles, contact [FrankieOne <Icon icon="arrow-up-right-from-square" size={12} />](https://www.frankieone.com/contact-us).
</Info>

Once you're done securing your recovery codes, select **Done**. An email will also be sent to your registered email address to inform you that you have enabled multi-factor authentication.

<Frame caption="Sample email confirming MFA is enabled for account.">
  <img src="https://mintcdn.com/frankieone-f5583b1b/Q0p9n7SnI12Y4IML/images/v2/portal/cf1493d-MFA6_cr.png?fit=max&auto=format&n=Q0p9n7SnI12Y4IML&q=85&s=bd156ce362ef88697a4816f791fe2341" alt="Sample email confirming MFA is enabled for account." width="1006" height="755" data-path="images/v2/portal/cf1493d-MFA6_cr.png" />
</Frame>

### Email

If you selected to receive your authentication codes through email, the **Setting up MFA with email** will open.

<Frame caption="The 'Setting up MFA with email' modal.">
  <img src="https://mintcdn.com/frankieone-f5583b1b/aMfFq_kgPrWD4cV3/images/v2/portal/5a00632-MFA7-EMAIL_cr.png?fit=max&auto=format&n=aMfFq_kgPrWD4cV3&q=85&s=a9a4d7bc2e35438af08dc03c8487af38" alt="The 'Setting up MFA with email' modal." width="884" height="497" data-path="images/v2/portal/5a00632-MFA7-EMAIL_cr.png" />
</Frame>

Click **Next** to receive an authentication code in your email inbox.

<Frame caption="Email with the 6-digit authentication code.">
  <img src="https://mintcdn.com/frankieone-f5583b1b/aMfFq_kgPrWD4cV3/images/v2/portal/6d6fe00-MFA7-EMAIL7_cr.png?fit=max&auto=format&n=aMfFq_kgPrWD4cV3&q=85&s=9114cf1fe3690508536f240643365d94" alt="Email with the 6-digit authentication code." width="974" height="731" data-path="images/v2/portal/6d6fe00-MFA7-EMAIL7_cr.png" />
</Frame>

Copy the 6-digit authentication code and enter it in the provided field in the **Enter the 6-digit authentication code** modal in the portal.

<Frame caption="The 'Enter the 6-digit authentication code' modal.">
  <img src="https://mintcdn.com/frankieone-f5583b1b/aMfFq_kgPrWD4cV3/images/v2/portal/42515aa-MFA7-EMAIL4_cr.png?fit=max&auto=format&n=aMfFq_kgPrWD4cV3&q=85&s=1fdbcacb954f9860ea531c6203b9f9cc" alt="The 'Enter the 6-digit authentication code' modal." width="884" height="497" data-path="images/v2/portal/42515aa-MFA7-EMAIL4_cr.png" />
</Frame>

If you don't receive an email with the 6-digit code within 5 minutes, select **Resend code** to request a new one.

<Info>
  Resend code limit

  Please note that you can only request a new code 5 consecutive times per session. Afterwards, this option will be disabled for 30 minutes. Try again after the hold period, and make sure to check your inbox and spam folder for the email with the code.
</Info>

<Frame caption="Resend code limit.">
  <img src="https://mintcdn.com/frankieone-f5583b1b/kuSfFEj6euwHKbOF/images/v2/portal/17ceedc-resend-limit.png?fit=max&auto=format&n=kuSfFEj6euwHKbOF&q=85&s=bd14d037918d1d421c7e74c8221dc7c5" alt="Resend code limit." width="1042" height="498" data-path="images/v2/portal/17ceedc-resend-limit.png" />
</Frame>

Select **Verify**. A confirmation modal will appear to let you know that multi-factor authentication is now enabled for your account.

<Frame caption="Multi-factor authentication is enabled.">
  <img src="https://mintcdn.com/frankieone-f5583b1b/Q0p9n7SnI12Y4IML/images/v2/portal/c68e37d-image.png?fit=max&auto=format&n=Q0p9n7SnI12Y4IML&q=85&s=a343fb9883e7d815de78e56304cbb503" alt="Multi-factor authentication is enabled." width="889" height="491" data-path="images/v2/portal/c68e37d-image.png" />
</Frame>

Select **Done**. An email will also be sent to your registered email address to inform you that you have enabled multi-factor authentication.

<Frame caption="Sample email confirming MFA is enabled for account.">
  <img src="https://mintcdn.com/frankieone-f5583b1b/aMfFq_kgPrWD4cV3/images/v2/portal/34310b5-MFA6_cr.png?fit=max&auto=format&n=aMfFq_kgPrWD4cV3&q=85&s=77483300a6c0cd6ad196ec946d10e06b" alt="Sample email confirming MFA is enabled for account." width="1006" height="755" data-path="images/v2/portal/34310b5-MFA6_cr.png" />
</Frame>

Additionally, a pop-up notification will appear on the lower-right corner of the portal to let you know that multi-factor authentication has been enabled.

<Frame caption="Pop-up notification when MFA is enabled.">
  <img src="https://mintcdn.com/frankieone-f5583b1b/Q0p9n7SnI12Y4IML/images/v2/portal/d41842c-image.png?fit=max&auto=format&n=Q0p9n7SnI12Y4IML&q=85&s=be1a5c6ec47c685405d80e8534dd9fe9" alt="Pop-up notification when MFA is enabled." width="826" height="578" data-path="images/v2/portal/d41842c-image.png" />
</Frame>

## Managing multi-factor authentication

Once MFA has been activated in your account, you can also disable it, if needed. One example would be when you need to change the MFA method from authentication app to email, or the other way around.

To disable MFA for your account, select **Disable MFA** on the **Settings** page, **Personal** tab.

<Frame caption="Personal tab in Settings page.">
  <img src="https://mintcdn.com/frankieone-f5583b1b/Q0p9n7SnI12Y4IML/images/v2/portal/ce27650-image.png?fit=max&auto=format&n=Q0p9n7SnI12Y4IML&q=85&s=b20ee0f2bd647ef2d445a8827dea8cf0" alt="Personal tab in Settings page." width="681" height="334" data-path="images/v2/portal/ce27650-image.png" />
</Frame>

A modal appears to warn you about disabling MFA.

<Frame caption="Disable multi-factor authentication modal.">
  <img src="https://mintcdn.com/frankieone-f5583b1b/Q0p9n7SnI12Y4IML/images/v2/portal/c22c158-image.png?fit=max&auto=format&n=Q0p9n7SnI12Y4IML&q=85&s=1fcb4f85e8d7937eba9e9f83a0f51569" alt="Disable multi-factor authentication modal." width="931" height="470" data-path="images/v2/portal/c22c158-image.png" />
</Frame>

If you are sure you want to disable MFA, select **Confirm**. The feature will be disabled and a pop notification will appear on the lower-right corner of the page.

<Frame caption="MFA has been disabled.">
  <img src="https://mintcdn.com/frankieone-f5583b1b/aMfFq_kgPrWD4cV3/images/v2/portal/2cc1932-image.png?fit=max&auto=format&n=aMfFq_kgPrWD4cV3&q=85&s=dab6ce3e760d3b06fc860f2d5cd7e090" alt="MFA has been disabled." width="949" height="522" data-path="images/v2/portal/2cc1932-image.png" />
</Frame>

An email will also be sent to your registered email confirming you have disabled MFA.

<Frame caption="Confirmation email that MFA has been disabled for your account.">
  <img src="https://mintcdn.com/frankieone-f5583b1b/Q0p9n7SnI12Y4IML/images/v2/portal/cfb10a2-image.png?fit=max&auto=format&n=Q0p9n7SnI12Y4IML&q=85&s=bf7147e059a25fbb0f7df797d0fc5e9d" alt="Confirmation email that MFA has been disabled for your account." width="926" height="739" data-path="images/v2/portal/cfb10a2-image.png" />
</Frame>

### Checking users with MFA

If you have an admin account, you can check which users have MFA enabled for their accounts. This can be important if part of your security policy is ensuring all users have MFA enabled.

To check if MFA is enabled for users, visit the **User Management** tab, and check the column **MFA Status**. Users with MFA enabled will be marked **Enabled**, and those that don't will be marked **Disabled**.

<Frame caption="User Management tab in the Settings page.">
  <img src="https://mintcdn.com/frankieone-f5583b1b/7CDIze6_8GRGrpBN/images/v2/portal/92ff09b-image.png?fit=max&auto=format&n=7CDIze6_8GRGrpBN&q=85&s=7d84e4900be23cfe6739399a73d32334" alt="User Management tab in the Settings page." width="1287" height="590" data-path="images/v2/portal/92ff09b-image.png" />
</Frame>
