This topic describes how to enable multi-factor authentication.
Background information
Multi-factor authentication (MFA) is a security mechanism that requires users to provide two or more different types of authentication factors to confirm their identity, thereby enhancing the security of accounts or systems. After enabling MFA, you will be prompted for secondary verification during login. OceanBase Cloud supports configuring MFA at the organization level as well as for individual accounts. The details are as follows:
- When the organization administrator of any organization the account belongs to enables organization-level MFA verification, the account will automatically have MFA enabled upon the next login to the OB Cloud console. By default, secondary identity verification is performed by receiving a one-time verification code.
- After an organization administrator enables organization-level MFA, members within the organization cannot disable MFA in their personal account's security settings. However, they can change the MFA verification method to APP verification or one-time verification code verification. When both methods are enabled, APP verification is used by default. Users can switch between the two methods during MFA verification.
- If organization-level MFA is not enabled, members within the organization can independently enable or disable MFA in their personal account's security settings.
For operations related to organization-level MFA, see Organization information management.
Prerequisites
To use APP verification, download and install the Authenticator APP on your mobile device:
iOS: Search for and install Google Authenticator / Microsoft Authenticator / Aliyun / 1Password / LastPass / Authenticator from the App Store.
Android: Search for and install Google Authenticator / Microsoft Authenticator / 1Password / LastPass / Authenticator from the app market.
Procedure
Log in to the OB Cloud console and click User Preferences in the upper-right corner.

In the left navigation bar, click Security to access the security management page.

In the Multi-factor Authentication (MFA) section, select the switch to enable verification code or APP verification.

For verification code, enter your email or mobile verification code in the pop-up box.

For APP verification, you must first verify your email.

Then, scan the QR code with your mobile device and enter the verification code.
Note
If you cannot scan the QR code, you can bind a text key.
After binding, MFA verification will be required for subsequent logins.
What to do next
To disable MFA verification, click the switch and enter the verification code to disable it for the current account's login. Proceed with caution.
Note
If an organization the current account belongs to has enabled MFA verification, individuals cannot disable it proactively.
