This topic uses the Google Authenticator app as an example to describe how to bind a multi-factor authentication (MFA) device to an Alibaba Cloud account. After an MFA device is bound, the MFA device provides additional security protection for your Alibaba Cloud account.
Prerequisites
The Google Authenticator app is downloaded and installed on your mobile device. You can use one of the following methods to download the Google Authenticator app:
For iOS, download the Google Authenticator app from the App Store.
For Android, download the Google Authenticator app from your preferred app store.
NoteFor Android, you must also download and install a quick response (QR) code scanner from an app store for Google Authenticator to identify QR codes.
Procedure
Log on to the Alibaba Cloud Management Console with an Alibaba Cloud account.
Move the pointer over the profile picture in the upper-right corner of the console, and click Security Settings.
In the Account Protection section of the Security Settings page, click Edit.
NoteMFA is renamed Time-based One-time Password (TOTP).
On the Turn on Account Protection page, select scenarios and the TOTP verification method. Then, click Submit.
In the Verify identity step, select a verification method.
In the Install the application step, click Next.
On your mobile device, bind a virtual MFA device.
NoteThe following example shows how to bind a virtual MFA device in the Google Authenticator app on your mobile device that runs iOS.
Open the Google Authenticator app.
Click Get started and select one of the following methods to enable a virtual MFA device:
Tap Scan a QR code in the Google Authenticator app and scan the QR code that is displayed in the Enable the MFA step of the Alibaba Cloud Management Console. This method is recommended.
Tap Enter a setup key, enter an account and the key of the account, and then tap Add.
NoteIn the Enable the MFA step of the Alibaba Cloud Management Console, move the pointer over Scan failed to view the account and key.
In the Enable the MFA step of the Alibaba Cloud Management Console, enter the dynamic verification code that is displayed in the Google Authenticator app. Then, click Next to complete the account protection settings.
NoteVerification codes in the Google Authenticator app are updated at an interval of 30 seconds.
What to do next
If you use the Alibaba Cloud account to log on to the Alibaba Cloud Management Console after you bind the virtual MFA device, you are prompted to enter the following verification information:
Enter the username and password of the RAM user.
Enter the verification code that is generated by the virtual MFA device.
After you bind an MFA device to an Alibaba Cloud account, the MFA device takes effect only on the Alibaba Cloud account and does not affect the logon of RAM users.
Before you uninstall the Google Authenticator app or remove the MFA device that is bound to the Google Authenticator app, you must unbind the MFA device in the Alibaba Cloud Management Console. Otherwise, you cannot log on to the Alibaba Cloud Management Console. For more information, see Unbind an MFA device from an Alibaba Cloud account.