Multi-Factor Authentication (MFA)
What Is Multi-Factor Authentication (MFA)?
Multi-Factor Authentication (MFA) adds an extra layer of security to your Krutrim Cloud account by requiring a second form of verification in addition to your password.
After entering your password, you must provide a 4-digit verification code generated by an authenticator application. This helps protect your account even if your password is compromised.
MFA is available for both Root Users and IAM Users.
How MFA Works
Krutrim Cloud uses the Time-based One-Time Password (TOTP) standard.
During MFA setup:
Krutrim Cloud generates a unique MFA secret.
The secret is converted into a QR code.
You scan the QR code using a compatible authenticator application.
The authenticator app generates a new six-digit code every 30 seconds.
Enter the OTP to complete MFA enrollment.
Once enrolled, MFA verification is required whenever your account requests additional authentication.
MFA Lifecycle
Setup MFA
↓
Scan QR Code
↓
Verify OTP
↓
Enrollment Complete
↓
Backup Codes Generated
↓
MFA Verification
↓
(Optional)
Un-enroll
MFA Features
Krutrim Cloud supports the following MFA capabilities:
Feature
Description
Setup MFA
Generates an MFA secret and QR code for enrollment
Enrollment Confirmation
Verifies the first OTP and completes enrollment
OTP Verification
Validates authenticator app codes
Backup Codes
Provides one-time recovery codes for emergency login
Un-enrollment
Removes MFA from the account after successful verification using either an OTP or a backup code
MFA Information
Retrieves the current MFA status
Setting Up MFA
To enable MFA:
Navigate to My account → Multi-Factor Authentication
Select Enable MFA
Scan the QR code using your authenticator application.
Enter the generated OTP.
Complete MFA enrollment.
After successful enrollment:
MFA becomes active.
Ten backup codes are generated.
Backup codes are displayed only once.
Backup codes should be stored securely for future recovery.
Backup Codes
Backup codes provide emergency access when your authenticator device is unavailable.
Characteristics:
10 backup codes are generated after successful enrollment.
Backup codes are not generated during MFA setup.
They are generated only after successful enrollment confirmation.
Each backup code can be used only once.
Used backup codes become permanently invalid.
Backup codes do not expire but remain valid until used, regenerated, or MFA is reset.
Un-enrolling MFA
Un-enrollment allows you to permanently remove Multi-Factor Authentication from your account.
To un-enroll MFA, you must authenticate using either:
A valid OTP generated by your authenticator application, or
A valid unused backup code.
Upon successful un-enrollment:
MFA is disabled for the account.
The stored MFA secret is removed.
All backup codes are deleted.
The MFA enrollment status is reset.
MFA verification status is cleared from all active sessions.
If you want to enable MFA again in the future, you must perform the complete MFA setup and enrollment process.
Security Considerations
Krutrim Cloud follows several security practices for MFA:
MFA secrets are generated uniquely per user.
Backup codes are single-use.
OTPs expire automatically based on the TOTP time window.
Previously used OTPs cannot be reused.
MFA verification is required before sensitive MFA operations.
Password policy can enforce mandatory MFA across an organization.
Audit Logging
For security and compliance purposes, MFA-related activities are recorded in the audit trail.
Examples include:
MFA setup
Enrollment confirmation
OTP verification
MFA enable or disable operations
MFA un-enrollment
Best Practices
Recommended practices:
Store backup codes in a secure location.
Complete MFA enrollment immediately after setup.
Keep your authenticator application on a trusted device.
Save your backup codes before leaving the enrollment page.
Never share your MFA secret or backup codes.
Last updated
Was this helpful?

