Set up multi-factor authentication
To set up multi-factor authentication, start with a signed-in account and a documented reason for the security or governance task. In Admin, start enrolment, scan authenticator code, verify current code, and complete enrolment. Use the least access needed, verify the subject and scope, and keep secrets and personal data out of notes and support evidence.
Before you start
- A signed-in account and a documented reason for the security or governance task
- The current user’s own email or identity when the task is personal
Steps
- Open /settings/mfa while signed in as the user who will own the authenticator.
- Start enrolment and scan the displayed authenticator secret or QR code using that user’s trusted device.
- Enter the current authenticator code once and submit before it expires.
- Wait for enrolment confirmation; never send the QR code, secret, or one-time code to Support.
Expected result
Successful enrolment shows MFA enabled for the signed-in user. Invalid or expired codes leave enrolment incomplete, and the authenticator secret, QR code, and one-time code are never treated as support evidence.
Permissions
- MFA enrolment requires auth.write and always applies to the currently signed-in user.
Troubleshooting
The authenticator code is rejected.
Confirm the code comes from the newly enrolled secret and enter the current code once before it expires. Restart enrolment only after the page shows failure; never send the QR code, secret, or code to Support.
MFA status remains uncertain.
Reopen /settings/mfa for the same signed-in user and check the enabled state before repeating enrolment. Give Support the route, time, and displayed error only, with no authentication secret.
Related articles
Request the signed-in person’s data export or account deletion once and track the returned status.Review audit and communication history
Filter and preserve scoped audit or communication evidence without treating the history as editable data.Review access approval requests
Review one access request and approve only the justified scope or reject it with a recorded reason.
Open in TajerGo
Sign in with the appropriate role and confirm your Business Account and branch before continuing.
Read as Markdown · Guidance for support agents
Last reviewed 2026-09-06 · Send documentation feedback