Multi-Factor Authentication (MFA)
Multi-Factor Authentication (MFA) adds an additional layer of security to your IoT.live Portal account.
When MFA is enabled, you’ll be required to enter a verification code after signing in with your password.
[IMAGE PLACEHOLDER: MFA verification screen]
Supported MFA methods
The IoT.live Portal currently supports:
Method | Description |
|---|---|
Email verification code | A temporary 6-digit code sent to your email address |
Authenticator app | A time-based code generated by an authentication app |
Supported authenticator apps include:
- Google Authenticator
- Microsoft Authenticator
- Twilio Authy
Sign in with MFA
- Enter your username and password.
- Complete the MFA verification step.
- Enter the verification code.
- Continue to the portal.
Verification codes sent by email are time-limited and expire automatically.
Use an authenticator app
Authenticator apps generate secure time-based verification codes directly on your device.
To configure an authenticator app:
- Open your user security settings.
- Select Authenticator App as your preferred MFA method.
- Scan the QR code using your authenticator app.
- Enter the generated verification code.
- Save your settings.
[IMAGE PLACEHOLDER: QR code pairing screen]
Fallback to email verification
If you cannot access your authenticator app during sign-in, you can choose to receive a verification code by email instead.
[IMAGE PLACEHOLDER: Email fallback option]
Organisation-wide MFA enforcement
Organisation administrators can enforce MFA for all users within an account.
When MFA is enforced at account level:
- All users must use MFA
- Individual users cannot disable MFA themselves
Security protection
The platform includes built-in protections against:
- Brute-force login attempts
- Repeated invalid MFA submissions
- Suspicious authentication activity
Repeated failed MFA attempts may temporarily lock your account for security reasons.