# Set up multi-factor authentication

To set up multi-factor authentication, start with a signed-in account and a documented reason for the security or governance task. In Admin, start enrolment, scan authenticator code, verify current code, and complete enrolment. Use the least access needed, verify the subject and scope, and keep secrets and personal data out of notes and support evidence.

Canonical URL: https://admin.tajergo.ae/help/articles/admin/mfa/
Article ID: mfa
Surface: Admin
Category: Security and governance
Last reviewed: 2026-09-06

## Before you start

- A signed-in account and a documented reason for the security or governance task
- The current user’s own email or identity when the task is personal

## Steps

1. Open /settings/mfa while signed in as the user who will own the authenticator.
2. Start enrolment and scan the displayed authenticator secret or QR code using that user’s trusted device.
3. Enter the current authenticator code once and submit before it expires.
4. Wait for enrolment confirmation; never send the QR code, secret, or one-time code to Support.

## Expected result

Successful enrolment shows MFA enabled for the signed-in user. Invalid or expired codes leave enrolment incomplete, and the authenticator secret, QR code, and one-time code are never treated as support evidence.

## Permissions

- MFA enrolment requires auth.write and always applies to the currently signed-in user.

## Troubleshooting

### The authenticator code is rejected.

Confirm the code comes from the newly enrolled secret and enter the current code once before it expires. Restart enrolment only after the page shows failure; never send the QR code, secret, or code to Support.

### MFA status remains uncertain.

Reopen /settings/mfa for the same signed-in user and check the enabled state before repeating enrolment. Give Support the route, time, and displayed error only, with no authentication secret.

## Related articles

- [Manage personal privacy data](https://admin.tajergo.ae/help/articles/admin/privacy-data.md)
- [Review audit and communication history](https://admin.tajergo.ae/help/articles/admin/audit-history.md)
- [Review access approval requests](https://admin.tajergo.ae/help/articles/admin/approvals.md)
