---
title: Multi-factor authentication (MFA)
description: Set up a second authentication factor, in addition to login and password
documentId: access-control-mfa
locale: en-US
---

## Configuring multi-factor authentication

To configure Multi-Factor Authentication (MFA) for the user you are logged in with:

<Steps>

<Step>
Click the icon in the upper right corner of the screen.  
![highlight for access icon](https://creative-ball-51b3fc85c0.media.strapiapp.com/accessing_access_control_settings_37e264ee69.png)
</Step>

<Step>
Then click **My Account Settings**.  
<img src="https://creative-ball-51b3fc85c0.media.strapiapp.com/my_account_settings_a660616c28.png" alt="highlight for my account settings" width="20%" />
</Step>

<Step>
In the screen that opens, click **Enable MFA**.  
![highlight for MFA activation](https://creative-ball-51b3fc85c0.media.strapiapp.com/enable_mfa_994df0bdd5.png)
</Step>

<Step>
Have your phone in hand to manually enter the code that appears on the screen or scan the QR Code.  
You can use the authentication app of your choice.  
![screen for MFA authentication](https://creative-ball-51b3fc85c0.media.strapiapp.com/enable_mfa_authentication_a21139ac34.png)
</Step>

<Step>
Enter the code generated by the authentication app and click **Enable MFA**.

Once activated, in addition to your password, you must enter the code provided by the chosen authentication app to log in.
</Step>

</Steps>

<Callout type="NOTE" title="NOTE">
MFA usage is not available for federated users.
</Callout>

## Disabling multi-factor authentication

### Disable MFA for your own user

When disabling MFA, you return to accessing only with your login and password, without the need to enter the security code.

To disable MFA for your user, repeat the process described above, clicking in the upper right corner of the screen, then **My Account Settings** and **Disable MFA**.

Every user can activate and deactivate their own MFA.

### Disable MFA for another user

When disabling MFA for another user, you allow the user to return to accessing only with their login and password, without the need to enter the security code.

<Callout type="NOTE" title="NOTE">
Your user needs permission to disable MFA for another user.
</Callout>

To disable MFA for another user, follow these steps:
<Steps>

<Step>
Click the icon in the upper right corner of the screen and **Access Control Settings**.  
![highlight for Access Control Settings](https://creative-ball-51b3fc85c0.media.strapiapp.com/access_control_settings_bf35ed4226.png)
</Step>

<Step>
In the card in the center of the screen or in the left sidebar menu, click **Users**.  
In the user list, click **>** in the **Actions** column of the desired user.  
![Users screen](https://creative-ball-51b3fc85c0.media.strapiapp.com/users_a41ae5448d.png)
</Step>

<Step>
Click **Disable MFA**.  
![highlight for MFA deactivation](https://creative-ball-51b3fc85c0.media.strapiapp.com/disable_mfa_514d34ae37.png)
</Step>

</Steps>

On this screen it is not possible to activate MFA.
