Multi-factor authentication (MFA) FAQ
Find answers to common MFA questions, including verification code errors, authentication failures, device replacement, and enforcing or disabling MFA, secure phone issues, and security email address issues.
Verification code error during MFA binding
MFA is time-based. Ensure the time on your mobile device is synchronized.
MFA codes refresh every 30 seconds. Enter the latest unused code.
The QR code (key) can expire if the binding page stays open too long. Refresh the page and scan a new QR code.
Scanning the QR code multiple times may create duplicate entries on your MFA device, each with a different code. This can cause authentication to fail. Delete any duplicates before scanning a new QR code.
Rebind the MFA device. Steps vary by account type:
Rebind the MFA device for an Alibaba Cloud account.
Rebind the MFA device.
Rebind the MFA device for a RAM user.
If the Alibaba Cloud account owner allows RAM users to manage their own MFA devices, the RAM user can unbind and rebind independently. Otherwise, contact the account owner or a RAM administrator.
Unbind the MFA device.
Rebind the MFA device.
If the issue persists, submit a ticket. Include screenshots of the error page, your device's displayed time, the account name, and the operation timestamp.
MFA authentication failure during sign-in
MFA is time-based. Ensure the time on your mobile device is synchronized.
Verify that you entered the latest unused code for the correct account.
If you replaced the MFA device, use the code from the newly bound device.
Rebind the MFA device. Steps vary by account type:
Rebind the MFA device for an Alibaba Cloud account.
Rebind the MFA device.
Rebind the MFA device for a RAM user.
If the Alibaba Cloud account owner allows RAM users to manage their own MFA devices, the RAM user can unbind and rebind independently. Otherwise, contact the account owner or a RAM administrator.
Unbind the MFA device.
Rebind the MFA device.
If the issue persists, submit a ticket. Include screenshots of your device's displayed time, the authenticated account name, and the operation timestamp.
Authenticator app deleted or device lost
Alibaba Cloud account: Go to the Retrieve Login Name page, click Submit an Appeal on the identity verification page, select Unbind MFA security verification, and submit the appeal for processing by a specialist. For the detailed process, see Process and materials for submitting an account appeal when identity verification fails.
Do not use
passport.aliyun.com/havanaone/profile/password/reset_password.htm, which returns a 500 error and is no longer available.RAM user: Contact the account owner or a RAM administrator to disable MFA. How do I disable MFA for a RAM user's console sign-in?.
Replace an MFA device
To replace the MFA device for an Alibaba Cloud account or a RAM user, for example when moving the authenticator app to a new phone, follow these steps.
Replace MFA device for an Alibaba Cloud account
Log on to the Account Center.
Unbind the MFA device on Phone A.
Rebind the MFA device on Phone B.
Replace MFA device for a RAM user
If the Alibaba Cloud account owner allows RAM users to manage their own MFA devices, the RAM user can unbind and rebind independently. Otherwise, contact the account owner or a RAM administrator. Manage security settings for RAM users.
Log on to the RAM console.
Unbind the MFA device on Phone A.
Rebind the MFA device on Phone B.
Enforce MFA for RAM user sign-in
An Alibaba Cloud account owner or RAM administrator can enforce MFA for RAM users through user security settings and console logon settings.
Require all RAM users to use MFA
In the user security settings, set MFA for RAM user sign-in to Force all users. Manage security settings for RAM users.
Require specific RAM users to use MFA
In the user security settings, set MFA for RAM user sign-in to Depend on each user.
In the console logon settings for the RAM user, set MFA Required to Required.
Create a RAM user or Manage console logon settings for a RAM user.
After these settings take effect, RAM users must bind an MFA device at their next sign-in. After binding, they must enter a verification code for all subsequent sign-ins. Bind an MFA device as a RAM user.
Disable MFA for RAM user sign-in
Disabling MFA reduces account security. Assess the security risks of password compromise before disabling MFA.
To better protect your account and assets, this feature will be gradually rolled out by account UID starting August 26, 2024. RAM users with the AdministratorAccess system permission must use MFA for sign-in. MFA cannot be disabled for these users. Notice.
Unbinding an MFA device is not the same as disabling MFA. To disable MFA for console sign-in, you must modify both user security settings and console logon settings.
Modify user security settings for the RAM user.
In the user security settings, set MFA for RAM user sign-in to Depend on each user or Required Only for Unusual Logon. Manage security settings for RAM users.
Depend on each user: MFA is configured per user. Proceed to the next step.
Required Only for Unusual Logon: MFA is enforced only in untrusted sign-in environments, such as when the sign-in location or device changes. Otherwise, MFA is not required.
Modify console logon settings for the RAM user.
In the console logon settings for the RAM user, set MFA Required to Not Required. Manage console logon settings for a RAM user.
Binding limit reached for secure phone or email
Each phone number or email address supports up to five RAM users. Unbind from an existing user or use a different one.
Activation link request limit
Activation links are valid for 24 hours. If rate-limited, wait 1 or 15 minutes before retrying.
Console sign-in blocked by an unactivated secure phone
If a RAM user's secure phone was set during user creation but was not activated, and MFA is required for console sign-in, the RAM user cannot access the console. After sign-in, the RAM user is redirected to the Select the MFA method to bind page.
As an administrator, log on to the RAM console, find the target RAM user, go to the Authentication page, and click Activate next to secure phone in the MFA information section. An activation SMS message is sent to the secure phone. After the RAM user taps the confirmation link in the message, the secure phone is activated and the RAM user can sign in again to access the console.
In RAM MFA settings, make sure that Allowed MFA devices includes secure phone.
Secure phone or email method not appearing
Bind the phone number or email address, then enable the verification method in user security settings. Manage security settings for RAM users.
Incorrect binding, lost device, or compromised account
Contact the account owner or a RAM administrator to unbind the MFA device. Unbind an MFA device for a RAM user.
Not receiving SMS for secure phone
Check that your mobile phone has an active service, no overdue payments, and a stable signal.
Check if your phone has blocked numbers from Alibaba Cloud, and check your blocked messages or spam folder.
Not receiving email for security email
Verify that the bound email address is correct.
Check your spam folder in case the email was identified as spam.