Enable Multi-Factor Authentication
You can enforce Multi-Factor Authentication (MFA) on access to the PhoenixAI Cloud console. MFA adds an extra layer of security by requiring two or more forms of verification when users sign in, thereby significantly decreasing the likelihood of unauthorized access.
Only console users with the Account admin role can configure MFA enforcement or reset the MFA integration for a user.
Enforce MFA
Follow these steps to enforce MFA on users in your PhoenixAI account:
- Sign in to the PhoenixAI Cloud console.
- In the left-side navigation pane, choose Account > Account settings.
- On the IAM settings tab of the Account settings page, turn on the switch in the Multi-Factor Authentication section.
- In the message that appears, click Enable to enforce MFA.
After MFA is enforced, all console users are required to enable and sign in with MFA the next time they log in to the console. Users who have already enabled MFA are not affected.
Enable MFA
All Console users must enable and sign in with MFA after MFA is enforced.
Follow these steps to enable MFA:
- Open the PhoenixAI sign-in page in a browser.
- Confirm your Account ID by choosing an existing account or entering the account ID of a new account.
- Enter your business email and password, and click Sign in.
- On the Authenticator section of the Set up multi-factor authentication page, you can scan the provided QR code with your MFA app to automatically establish the integration, or copy the key for manual settings.
- After the integration is established, enter a 6-digit authentication code from your MFA app, and click Verify and continue.
- On Recovery codes section of the Set up multi-factor authentication page, copy and save the recovery codes properly. They can be used to sign in to the PhoenixAI Cloud console when you lose access to your MFA app.
- Select I have saved my recovery codes in a safe place, and then, click Finish enrollment.
Remove MFA enforcement
Follow these steps to remove the MFA enforcement:
- Sign in to the PhoenixAI Cloud console.
- In the left-side navigation pane, choose Account > Account settings.
- On the IAM settings tab of the Account settings page, turn off the switch in the Multi-Factor Authentication section.
- In the message that appears, click Turn off to remove the MFA enforcement.
After the MFA enforcement is removed, console users are no longer required to sign in with MFA. Users who have enabled MFA can disable it manually. For detailed instructions, see Disable MFA.
Disable MFA
If the MFA enforcement of the account has been removed, console users can disable MFA for login.
Follow these steps to disable MFA:
- Sign in to the PhoenixAI Cloud console.
- In the left-side navigation pane, click your username at the bottom, and then, click Security.
- On the Security page, click Disable in the Authenticator app section.
- On the dialog box that appears, enter a 6-digit authentication code from your MFA app, and click Turn off to disable MFA.
Regenerate recovery codes
You can regenerate the recovery codes if you have lost them.
Follow these steps to regenerate the recovery codes:
- Sign in to the PhoenixAI Cloud console.
- In the left-side navigation pane, click your username at the bottom, and then, click Security.
- On the Security page, click Regenerate in the Recovery codes section.
- On the dialog box that appears, enter a 6-digit authentication code from your MFA app, and click Regenerate to regenerate the recovery codes.
- On Save your recovery codes section of the Security page, copy and save the recovery codes properly.
- Select I have saved my recovery codes in a safe place, and then, click Done.
Reset MFA integration
If a user has lost both access to their MFA app and their recovery codes, they must contact a user with the Account admin role to reset MFA integration to allow them to sign in to the console again.
Follow these steps to reset the MFA integration for a user:
- Sign in to the PhoenixAI Cloud console.
- In the left-side navigation pane, choose Access Control > Members.
- On the Members page, search and find the user you want to reset MFA, and click Reset MFA in the Action field.
- On the message that appears, click Reset MFA.
After the MFA integration is reset, the user can enable and sign in with MFA the next time they log in to the console.