Who can use this feature?
Workspace Owners, Super Admins, Admins, and Users
Account Owners
Supported using the Cerby web app and mobile app. For the mobile app instructions, read the article Turn on MFA with Cerby as an authenticator app for your account using the mobile app
As an account Owner, you can turn on and manage multi-factor authentication (MFA) for your accounts using the Cerby web app. This process involves using a secret key or scanning a QR code.
Unlike traditional authenticator apps tied to a single device or user, Cerby generates and securely distributes time-based one-time passwords (TOTPs) to all users with shared access to the account.
When MFA is turned on with this verification method, Cerby fills in the six-digit security codes required during login. Therefore, you can reduce manual overhead, eliminate the need to share physical devices, and ensure consistent access for all users with account permissions, while maintaining a secure authentication process.
Requirements
The following are the requirements to set up and associate Cerby as your authenticator app for your account:
A Cerby workspace
A Cerby user account with the workspace Owner, Super Admin, Admin, or User role
An account in an app or service provider
An account added to Cerby to which you have the Owner role
Turn on MFA with Cerby as an authenticator app for your account
You can turn on MFA with Cerby as your authenticator app using the following methods:
Automatic setup: For supported managed apps, Cerby can automatically turn on MFA without requiring manual input. With one click, Cerby handles the entire setup process for you in the background, including saving the account backup or recovery codes when supported.
Manual setup: For apps that don’t support automation to turn on MFA, you can manually turn it on by retrieving a secret key from the app’s settings page and entering it in Cerby to complete the setup. Cerby recommends saving the account backup or recovery codes when supported.
The following sections describe the instructions for each option.
Automatic setup
For supported apps, you can turn on MFA automatically with a single click by completing the following steps in the Cerby web app:
Log in to your Cerby workspace.
Click the corresponding account card. The account details page is displayed.
Expand the Multi-factor authentication (MFA) settings section.
Click the Turn on button in the Cerby authenticator app section. The Turn on MFA dialog box is displayed.
Select the I’ve verified that MFA is off for this account option.
Click the Turn on MFA button. A message indicating that Cerby is turning on MFA is displayed; when the automation is complete, a success message is displayed.
NOTE: You can see the status of the automation job to turn on MFA in the Automation Log. When completed and supported, the account backup or recovery codes are saved in Cerby, and you can see them in the Emergency controls section of the account details page.
Now you are done.
Manual setup
For self-managed apps and managed apps that don’t support automation to turn on MFA, you can turn it on manually by completing the following steps using the Cerby web app:
Log in to your app in a web browser.
Navigate to the MFA page in your app settings.
Select the option to turn on MFA with an authenticator app. Commonly, a QR code is displayed.
Complete the steps that corresponds to the setup method you want to use:
Secret key
Select the Can’t scan code? or Show secret key option. An alphanumerical secret key is displayed.
Copy the secret key.
Open a separate browser tab.
Log in to your Cerby workspace.
Click the corresponding account card. The account details page is displayed.
Expand the Multi-factor authentication (MFA) settings section.
Click the Set as MFA button. The Save Code dialog box is displayed.
Paste the secret key in the Secret Key field of the Save Code dialog box.
Click the Save Code button. A six-digit code is displayed.
Copy the code.
QR code
Log in to your Cerby workspace using your Cerby mobile app.
Tap the corresponding account card to open the account details screen.
Tap the Activate MFA button. The mobile phone's camera is displayed.
Scan the QR code with your mobile phone. A six-digit code is displayed on a new screen.
Finish the MFA setup in your app by completing the following steps:
Switch to the browser tab with your app settings.
Paste or enter the six-digit code.
Save the configuration.
Switch to the browser tab with the Cerby web app or take your mobile phone.
Click the Done button. The dialog box or the screen closes, and a success message box is displayed.
Save the account backup or recovery codes in Cerby, if supported by the app, by following the instructions in the article Save the backup or recovery codes of your account.
Now you are done.
