This topic describes how to use multi-factor authentication (MFA) for your account.
Background information
Multi-factor authentication (MFA) is a security mechanism that requires users to provide two or more different types of authentication factors to verify their identity, thereby enhancing the security of accounts or systems. After MFA is enabled, you can use it for secondary authentication when you log in. OceanBase Cloud supports enabling MFA at the organization level and at the individual account level. The following describes the two methods:
- If the admin of any organization to which your account belongs enables MFA at the organization level, MFA will be automatically enabled for your account when you log in to the OceanBase Cloud console. By default, you will receive a one-time verification code for secondary authentication.
- After the admin of an organization enables MFA at the organization level, members of the organization cannot disable MFA in the security settings of their individual accounts. However, they can change the MFA verification method to either app-based verification or one-time verification code verification. When both methods are enabled, app-based verification is used by default, and you can switch between the two methods during MFA verification.
- If MFA is not enabled at the organization level, members of the organization can enable or disable MFA in the security settings of their individual accounts.
For more information about MFA at the organization level, see Manage organization information.
Prerequisites
If you want to use app-based verification, download and install an authenticator app on your mobile device:
iOS: Search for and install Google Authenticator, Microsoft Authenticator, Aliyun, 1Password, LastPass, or Authenticator in the App Store.
Android: Search for and install Google Authenticator, Microsoft Authenticator, 1Password, LastPass, or Authenticator in the app market.
Procedure
Log in to the OceanBase Cloud console and click User Preferences in the upper-right corner.
In the left-side navigation pane, click Security to go to the security management page.
In the Multi-factor Authentication (MFA) section, enable the verification code or app-based verification switch.
If you choose verification code, enter your email verification code in the pop-up window.
If you choose app-based verification, you need to verify your email first.
Then, use your mobile device to scan the QR code and enter the verification code.
Note
If you cannot scan the QR code, you can use the text key for binding.
After binding, MFA verification will be required for subsequent logins.
What to do next
If you want to disable MFA verification, click the switch, enter the verification code, and disable MFA verification for your account. Proceed with caution.
Note
If MFA verification is enabled for the organization to which your account belongs, you cannot disable it individually.