Background
Multi-Factor Authentication (MFA) is a simple and effective security authentication method. It adds an extra layer of protection outside username and password. When logging in with the password of an Identity Management of Group Account, MFA authentication will be forced open to strengthen service security. This document describes detailed operations for Identity Management users to add or delete an MFA device.
Operation Steps
Adding an MFA Device
MFA login protection is enabled by default. When an Identity Management user logs in to the User Portal with username and password, and the MFA login protection status is MFA device to be bound, they will be required to add an MFA device.
The MFA login protection status MFA device to be bound has two scenarios:
logging in for the first time
Admin deleted the MFA device
Adding an MFA Device Procedure
1. Identity Management users click to access User Login URL, enter username and password, then click Log in.
2. Enter the Enable MFA device verification page. This example uses an Android phone with Google Authenticator for demonstration.
Note:
Users are advised to download an MFA device support app on a mobile device (such as a mobile phone). Google Authenticator and Microsoft Authenticator are now supported.
3. On your Android phone, open the Microsoft Authenticator app, click Scan QR code, and scan the QR code on the Enable MFA Device Verification page to add a device.
4. After successful addition, the Tencent Cloud CIC Services app is added on your mobile device. Enter the displayed 6-digit Captcha into the Enter MFA Captcha field on the Enable MFA Device Verification page, then click Confirm.
5. After successful verification, enter the Identity Management account selection page.
Deleting an MFA Device
2. In the left sidebar, select User Management > User.
3. On the User List page, click the target username to enter the User Details page.
4. Click the Security Information tab, then click Unbind in the MFA Login Protection module.
5. In the MFA device deletion dialog box, click Confirm Unbinding to complete the deletion.
Note:
Next time when logging in, the user must rebind the MFA device.