AccountUpdated
Secure your account
Turn on authenticator app MFA with a QR code or setup key and review or sign out the devices signed in to your account.
accountsecuritymfa
The Security settings page covers two protections: an authenticator app code required after password sign-in, and a list of every device currently signed in to your account so you can remove access you do not recognise.
Before you start
- Sign in to the account you want to protect.
- Install an authenticator app on your phone, such as any standard TOTP app that scans QR codes.
- Authenticator MFA applies to password sign-in; social sign-in users are not prompted for this password-flow step.
Set up authenticator app MFA
- Open Settings > Account > Security and find the Authenticator app MFA card. The status shows Enabled or Not enabled.
- Select Set up authenticator app.
- Scan the QR code with your authenticator app, or enter the Manual setup key by hand.
- Type the 6-digit code from your app into the Authenticator code field and select Verify and enable.
- To turn it off later, select Disable authenticator app on the same card.
Review signed-in devices
- On the same page, open Signed-in devices to see each device with its browser, signed-in date, last seen time, and IP hint.
- Your current device is marked Current device and stays signed in.
- Select any devices you do not recognise and use Sign out selected, or use the device menu to sign out a single device.
Expected result
With MFA enabled, password sign-in asks for a 6-digit authenticator code after your password. Signed-out devices lose access immediately and must sign in again, while your current session continues working.
Troubleshooting
- If code verification fails, check that your phone's clock is accurate and enter a fresh code; each code is valid only briefly.
- If a device could not be signed out, refresh the page and try again; the current device cannot be removed from this list.
- If you lose access to your authenticator app but still have a signed-in device, open Settings > Account > Security there and select Disable authenticator app, then re-enrol with your new app.
Was this helpful?