> For the complete documentation index, see [llms.txt](https://docs.couchdrop.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.couchdrop.io/security-and-governance/user-and-account-policies/multi-factor-authentication-mfa.md).

# Multi-Factor Authentication (MFA)

Learn about configuring MFA/2fa in Couchdrop

## Overview

MFA adds an additional authentication step when users sign in to Couchdrop.

Users can configure MFA using **SMS** or an **authenticator app**, such as Microsoft Authenticator, Google Authenticator, or 1Password. Administrators can also require MFA across the Couchdrop account and disable SMS as an available authentication method.

{% hint style="info" %}
MFA only applies to the **Couchdrop Web App**. Enabling or enforcing MFA does not affect authentication over SFTP, SCP, FTP, or FTPS.
{% endhint %}

## Configuring MFA as a user

Users can configure and manage MFA from their profile in Couchdrop.

Once MFA has been configured, the user will be required to complete the additional authentication step when signing in to the web interface.

## Enforcing MFA

You can require users to configure MFA before they can access the Couchdrop Web App.

Navigate to **Admin Panel > Security & Org > Policies**.

Under **Enforce MFA**, enable:

**Require users to configure MFA before logging into Couchdrop**

When enabled, users who have not configured MFA will be required to set it up the next time they sign in.

New users will also be required to configure MFA during their first sign-in.

Users can configure MFA using either SMS or an authenticator app unless SMS has been disabled for the account.

## Disabling SMS authentication

If you do not want users to authenticate using SMS, navigate to **Admin Panel > Security & Org > Policies** and enable:

**Disable SMS as an MFA option**

When enabled:

* Users cannot select SMS when configuring MFA.
* Existing users currently using SMS for MFA will be required to configure an authenticator app the next time they sign in.

This allows you to require authenticator app-based MFA across the account.

## Resetting MFA for a user

Couchdrop administrators with permission to manage users can disable MFA for an individual user.

After MFA has been disabled, the user can sign in without their existing MFA configuration and configure MFA again.

{% hint style="warning" %}
Administrators cannot disable MFA for the account owner. Contact Couchdrop Support if you are unable to access the owner account.
{% endhint %}
