Overview
Multi-Factor Authentication (MFA) adds an additional security layer to your Elementum account by requiring a time-based verification code during login. Even if your password is compromised, unauthorized users cannot access your account without the code from your authenticator app. Key Benefits:- Reduced Risk: Compromised passwords alone cannot grant account access
- Industry Standard: Uses TOTP (Time-based One-Time Password) protocol supported by all major authenticator apps
- User Control: Enable or disable MFA from your account settings at any time
- Simple Setup: Configure in minutes with any compatible authenticator app
Who Should Enable MFA
Recommended For
- Users with access to sensitive business data
- Organization administrators
- Users managing automations and integrations
- Anyone seeking enhanced account security
Especially Important For
- Accounts not protected by SSO/SAML
- Users accessing Elementum from multiple devices
- Accounts with elevated permissions
- Compliance-sensitive environments
If your organization uses SSO with an Identity Provider that already enforces MFA (such as Okta or Azure AD with MFA policies), you may already have multi-factor protection at the IdP level.
Supported Authenticator Apps
MFA works with any authenticator app that supports the TOTP standard, including:| App | Platforms | Notes |
|---|---|---|
| Google Authenticator | iOS, Android | Free, simple interface |
| Microsoft Authenticator | iOS, Android | Includes backup and cloud sync |
| Okta Verify | iOS, Android | Common in enterprise environments |
| 1Password | iOS, Android, Desktop | Integrated with password management |
| Authy | iOS, Android, Desktop | Multi-device sync and backup |
| Duo Mobile | iOS, Android | Enterprise-focused with push options |
Setting Up MFA
Prerequisites
Before enabling MFA, ensure you have:- An Elementum account with password-based authentication
- A smartphone or device with an authenticator app installed
- Access to scan a QR code or manually enter a setup key
Step-by-Step Setup
Navigate to Account Security
- Click your profile icon in the bottom-left corner of Elementum
- Navigate to the Security tab
Initiate MFA Setup
- Locate the Multi-Factor Authentication section
- Click Enable MFA to begin setup
- A QR code will be displayed on screen
Scan the QR Code
- Open your authenticator app on your mobile device
- Select the option to add a new account (usually a + icon)
- Choose Scan QR code or Scan barcode
- Point your device camera at the QR code displayed in Elementum
Can't scan the QR code?
Can't scan the QR code?
If you cannot scan the QR code (e.g., using a desktop authenticator or camera issues):
- Click Can’t scan? Enter code manually below the QR code
- Copy the secret key displayed
- In your authenticator app, select Enter setup key manually
- Enter:
- Account name: Your Elementum email or “Elementum”
- Secret key: Paste the copied key
- Type: Time-based (TOTP)
Verify and Activate
- Your authenticator app will display a 6-digit code that refreshes every 30 seconds
- Enter the current code in the Verification code field in Elementum
- Click Verify and Enable
- You’ll see a confirmation message that MFA is now active
Logging In with MFA
Once MFA is enabled, your login process includes an additional verification step:Enter Your Credentials
- Navigate to the Elementum login page
- Enter your email address
- Enter your password
- Click Log In
Enter Authenticator Code
- You’ll be prompted to enter your authenticator code
- Open your authenticator app
- Find your Elementum account entry
- Enter the 6-digit code currently displayed
- Click Verify
Codes refresh every 30 seconds. If your code is about to expire (timer nearly empty), wait for the next code to ensure you have enough time to enter it.
Managing MFA
Viewing MFA Status
To check your current MFA status:- Go to Account Settings > Security
- The Multi-Factor Authentication section displays:
- Enabled: MFA is active on your account
- Disabled: MFA is not configured
Disabling MFA
To disable MFA:Disable MFA
- In the Multi-Factor Authentication section, click Disable MFA
- You may be prompted to enter your password or current authenticator code to confirm
- Click Confirm to disable MFA
Best Practices
Use an authenticator with backup
Use an authenticator with backup
Choose an authenticator app that supports cloud backup or multi-device sync (Microsoft Authenticator, Authy, 1Password). This makes device transitions seamless and provides recovery options.
Don't share screenshots of QR codes
Don't share screenshots of QR codes
Keep your authenticator app updated
Keep your authenticator app updated
Ensure your authenticator app is updated to the latest version for security patches and compatibility.
Plan for device changes
Plan for device changes
Before switching phones or resetting your device:
- Disable MFA in Elementum while you still have access
- Set up your new device
- Re-enable MFA with a fresh QR code scan
Verify your device clock
Verify your device clock
TOTP codes depend on accurate time. Enable automatic time sync on your device to prevent code validation issues.
Related Documentation
MFA FAQ
Frequently asked questions about Multi-Factor Authentication
SSO Configuration
Configure Single Sign-On with SAML 2.0 for centralized authentication
Last updated: January 2025