Common
Account security
Change your password and manage MFA, authenticators, and recovery codes.
What this menu does
Let every signed-in user strengthen and recover their own account without exposing security secrets to other users.
Where to find it
Open the account menu in the top-right corner, select Profile, then open Password or MFA settings.
When to use it
- Change the current password.
- Enable an authenticator app.
- Generate replacement recovery codes.
- Disable MFA after confirming the impact.
Before you begin
- Use an account issued for the intended portal.
- Use a supported desktop or mobile browser.
Page regions
- 01Profile and password settings
- 02MFA status
- 03Authenticator setup QR code
- 04Verification code field
- 05Recovery-code list
- 06Disable confirmation
Supported operations
Change your password
- 1
Open Profile and select Change password.
- 2
Enter the current password and the new password.
- 3
Submit the change.
- 4
Use the new password the next time you sign in.
The password changes for this account only.
Enable MFA
- 1
Open Profile and select Bind MFA.
- 2
Start setup and scan the QR code with an authenticator app; use the displayed secret only if scanning is unavailable.
- 3
Enter the current authenticator code and verify.
- 4
Copy the generated recovery codes to a secure offline location before closing the panel.
MFA becomes required on later sign-ins and recovery codes are issued once for safekeeping.
Regenerate recovery codes
- 1
Open Profile and Manage MFA.
- 2
Select Regenerate recovery codes.
- 3
Save the new codes securely.
- 4
Destroy any previously saved recovery-code list because old codes no longer apply.
A new recovery-code set replaces the previous set.
Disable MFA
- 1
Open Profile and Manage MFA.
- 2
Select Disable MFA.
- 3
Read the security impact and confirm.
- 4
Sign out and sign in again if you want to verify the new login behavior.
The factor and recovery codes are removed from the account.
Business rules and fields
- Never copy MFA secrets, QR codes, or recovery codes into tickets or chat.
- Recovery codes are single-use.
- Regenerating codes invalidates the previous set.
- Administrators can reset MFA for some managed accounts, but cannot retrieve the user's secret.
States you may see
What happens next
- Security changes apply to the signed-in account and are reflected in later login challenges.
- Sensitive setup values are not shown again after the setup flow closes.
Common problems
MFA setup or recovery-code generation fails.
The session security token is missing, the verification code is invalid, or the request failed.
Keep the panel open, use the newest authenticator code, and retry once. Sign in again if the page reports a missing session.