Skip to content

Two-Factor Authentication

IAM supports two-factor authentication (2FA TOTP) for user accounts to enhance account security.

Overview

2FA adds a layer of security to your account by requiring a second form of authentication beyond your password. We support TOTP (Time-based One-Time Password) tokens.

Enabling 2FA

IdP Federation

2FA as outlined here is not managed administratively but configured by users themselves. To enable 2FA administratively, connect your IdP to our platform.

Once the domain of the account you are using to login is federated, you will not be able to configure 2FA as outlined here. 2FA is then managed by the federated IdP.

  1. Login to the Dashboard.
  2. From the navigation menu, click on the user icon in the top right corner.

User Menu

  1. In the account menu, click on "Manage 2FA". Keycloak opens its account console.

Manage 2FA

  1. Click on "Set up authenticator application".

Set up authenticator application

  1. Follow the instructions on the screen to set up your authenticator application.

Set up authenticator application

The next time you login, you enter a 2FA token.