Step 3: Configure MFA for your account

Updated at:
Copy as MD

Configuring MFA for your Alibaba Cloud account is one of the best practices for protecting your assets on the cloud. This topic uses the Alibaba Cloud app as an example to describe how to attach a virtual MFA device to your Alibaba Cloud account.

What is MFA and why should I configure it?

MFA (Multi-Factor Authentication) is a best practice for improving account security. It adds an extra layer of protection beyond your username and password.

With MFA enabled, logging on to Alibaba Cloud requires the following two verification steps:

  1. First factor: Enter your username and password.

  2. Second factor: Another verification method, such as the 6-digit dynamic verification code that a virtual MFA device automatically generates every 30 seconds.

With two-factor authentication, even if your password is leaked, anyone without your mobile phone cannot log on to your account. This effectively prevents account theft and greatly improves security.

Which MFA methods do Alibaba Cloud accounts support?

Alibaba Cloud accounts currently support multiple MFA methods, such as text message verification codes. This topic focuses on virtual MFA devices (Virtual MFA Device), which are software-based multi-factor authentication applications. A virtual MFA app follows the TOTP (Time-based One-Time Password, RFC 6238) standard and generates a 6-digit dynamic verification code every 30 seconds for two-factor verification during logon and other critical operations.

Recommended virtual MFA apps

  • Alibaba Cloud app (recommended): The official app is highly integrated and supports one-stop Alibaba Cloud service management and security authentication.

  • Google Authenticator: A mainstream TOTP standard app, available for Android and iOS.

  • Other TOTP-compatible authenticators: such as Microsoft Authenticator and Authenticator (Windows Phone).

Attach a virtual MFA device

This topic uses the Alibaba Cloud app as an example. The steps for other TOTP-compatible apps are similar.

Prerequisites

Before you begin, make sure you meet the following requirements:

  • Your Alibaba Cloud account has completed identity verification. For more information, see Identity verification overview

  • You have downloaded and installed the latest version of the Alibaba Cloud app.

Procedure

  1. Log on to the Account Center. Under My Account, select Security. Then, click Virtual MFA next to Bind.

  2. On the Verify Identity page, select a suitable method to complete identity verification.

    The available verification methods include phone number verification, Alipay verification and face recognition.

  3. On the Enable MFA page, follow the on-screen instructions to download and install the Alibaba Cloud app or Google Authenticator on your mobile phone. Use the Alibaba Cloud app or Google Authenticator to obtain a verification code, enter the code, and then click Enable.

  4. After the MFA device is attached, refresh the Security page. The status changes to Bound. A Virtual MFA entry now shows an Unbind link. If you need to change the verification method or device, click this link to detach the MFA device.

FAQ

How do I attach an MFA device if my account is shared by multiple users?

You can share the QR code in Step 4 above and invite all users who need to use this account to scan the code once so that everyone adds the MFA device for this account. This way, each user can independently obtain dynamic verification codes to log on.

What should I do if I lose my phone or accidentally uninstall the Alibaba Cloud app and cannot use MFA?

This is a critical situation that might prevent you from logging on to your account!

  • Best practice: Before you replace your phone, reinstall the operating system, or uninstall the app, make sure to log on to the Alibaba Cloud Management Console and, in your security settings, detach the MFA device.

  • Emergency: If you have lost your phone or accidentally uninstalled the app, you cannot detach the device yourself. In this case, you must submit a manual appeal to detach the MFA device. For more information, see Attach or detach a virtual MFA device.