---
name: azion-enable-multi-factor-authentication
description: >-
  Turn on multi-factor authentication for a user or for every user of an account, and sign in to Azion Console with an authenticator code.
---

# Enable multi-factor authentication

You can turn on [multi-factor authentication (MFA)](/en/documentation/fundamentals/multi-factor-authentication/) for one user or for every user of an account from Azion Console. With MFA on, a user signs in with a password and a six-digit code from an authenticator application. To regain access after you lose the device that runs the authenticator, refer to [Troubleshoot Azion Console sign-in](/en/documentation/support/account-access/).

---

## Prerequisites

- Access to Azion Console as an **Account owner**. To sign in, refer to [Access Azion Console](/en/documentation/guides/platform/account-and-billing/how-to-access-azion-console/).
- An authenticator application on a mobile phone for each user who turns on MFA, such as Google Authenticator or Microsoft Authenticator. Install it from the app store of the phone's operating system.

---

## Turn on MFA for one user

An Account owner turns on MFA for any user of the account, including their own user, in **Users Management**.

To turn on MFA for a user in Azion Console:

1. **Open Users Management**

   Access [Azion Console](https://console.azion.com/) and, in the account menu, select **Users Management**.

2. **Select the user**

3. **Turn on MFA**

   In the **Security Settings** section, turn on **Enforce Multi-Factor Authentication**.

4. **Select Save**

The next time the user signs in, Azion Console opens the MFA setup page.

---

## Require MFA for every user of the account

The account setting makes MFA mandatory for all users linked to the account. While it is on, an Account owner cannot turn off MFA for a single user.

To require MFA for every user in Azion Console:

1. **Open Account Settings**

   Access [Azion Console](https://console.azion.com/) and, in the account menu, select **Account Settings**.

2. **Turn on the enforcement**

   In the **Login Settings** section, turn on **Enforce Multi-Factor Authentication**.

3. **Select Save**

Every user linked to the account must set up MFA at their next sign-in. To stop the enforcement, turn off **Enforce Multi-Factor Authentication** in the same section and select **Save**.

---

## Connect the authenticator application

The MFA setup page shows a QR code at the first sign-in after MFA is turned on. The authenticator application reads it and starts to generate six-digit codes for your Azion user.

To connect the authenticator application:

1. In the authenticator application, select **+**.
2. Select the account type to add. The camera of the phone starts.
3. Scan the QR code on the MFA setup page.
4. On the MFA setup page, enter the six-digit code and select **Verify code**.

Azion Console signs you in. From now on, each sign-in asks for a code from the same phone.

---

## Sign in with MFA

To sign in to Azion Console with MFA on:

1. On the sign-in page of Azion Console, enter your email and password, and select **Sign In**.
2. Open the authenticator application on your phone.
3. In Azion Console, enter the six-digit code and select **Verify**.

Azion Console opens after the code is verified.

---

## Turn off MFA for one user

A user who loses the phone that runs the authenticator cannot sign in until an Account owner turns off their MFA. The Account owner can do it only when **Enforce Multi-Factor Authentication** is off in **Account Settings**.

To turn off MFA for a user in Azion Console:

1. **Open Users Management**

   Access [Azion Console](https://console.azion.com/) and, in the account menu, select **Users Management**.

2. **Select the user**

3. **Turn off MFA**

   In the **Security Settings** section, turn off **Enforce Multi-Factor Authentication**.

4. **Select Save**

The user signs in with email and password only. When the locked-out user is the only Account owner of the account, Azion Support resets the MFA. To contact it, refer to [Open a support ticket](/en/documentation/support/open-tickets/).

---

## Next steps

- [Manage users](/en/documentation/guides/platform/account-and-billing/users-management.md): Add users to the account and set who is an Account owner.
- [Configure Account Lockout Policy](/en/documentation/guides/application-security/access-and-compliance/configure-account-lockout-policy.md): Lock a user after repeated failed sign-in attempts.
- [Troubleshoot Azion Console sign-in](/en/documentation/support/account-access.md): Regain access after you lose the MFA device.
- [Multi-factor authentication](/en/documentation/fundamentals/multi-factor-authentication.md): Read how MFA protects the sign-in to an account.
