How to Set Up Multi-Factor Authentication (MFA)
Add an extra layer of security to your Zuro account with Multi-Factor Authentication (MFA). MFA requires a second verification step when logging in, making your account more secure.
What is MFA?
Multi-Factor Authentication adds a second verification step to your login process. Even if someone has your password, they can't access your account without the second factor.
MFA Methods
Zuro supports two MFA methods:
TOTP (Authenticator App)
- Use apps like Google Authenticator, Authy, or Microsoft Authenticator
- Generate time-based codes
- Works offline
- Most secure option
Email MFA
- Receive verification codes via email
- Easier to use
- Requires email access
- Good for users who prefer email
Setting Up MFA
Step 1: Access MFA Settings
- Log in to your Zuro account
- Go to Settings → Security → Multi-Factor Authentication
- Click "Set Up MFA"
Step 2: Choose Your Method
Select either:
- TOTP (Authenticator App) - Recommended for most users
- Email MFA - Easier option if you prefer email
Step 3: Complete Setup
For TOTP:
- Install an authenticator app on your phone
- Scan the QR code with your app
- Enter the 6-digit code to verify
- Save your backup codes (important!)
- Click "Enable MFA"
For Email:
- Verify your email address is correct
- Click "Enable MFA"
- You'll receive codes via email when logging in
Using MFA
Logging In
- Enter your email and password
- You'll be prompted for your MFA code
- TOTP: Open your authenticator app and enter the 6-digit code
- Email: Check your email for the code and enter it
- Complete login
Backup Codes
Backup codes let you access your account if you lose access to your MFA method:
- Generate codes: Settings → Security → Multi-Factor Authentication → "Regenerate Backup Codes"
- Save securely: Store in a password manager or secure location
- One-time use: Each code can only be used once
- Generate new ones: Create new codes anytime (old ones become invalid)
Managing MFA
Disable MFA
- Go to Settings → Security → Multi-Factor Authentication
- Click "Manage MFA Settings" (or go to
/account/settings/mfa) - Click "Disable MFA"
- Enter your password to confirm
- MFA is removed from your account
Change MFA Method
- Disable your current MFA method
- Set up the new method
- Enable MFA with the new method
Regenerate Backup Codes
- Go to Settings → Security → Multi-Factor Authentication
- Click "Manage MFA Settings" (or go to
/account/settings/mfa) - Click "Regenerate Backup Codes"
- Save the new codes immediately
- Old codes will no longer work
Troubleshooting
Lost Access to Authenticator App
- Use your backup codes to log in
- Disable MFA and set it up again
- Contact support if you don't have backup codes
Not Receiving Email Codes
- Check your spam folder
- Verify your email address is correct
- Wait a few minutes and request a new code
- Check email service isn't blocking Zuro emails
Backup Codes Not Working
- Make sure you're using the most recent codes
- Each code can only be used once
- Generate new codes if needed
Best Practices
- Use TOTP for better security: Authenticator apps are more secure than email
- Save backup codes: Store them in a secure password manager
- Keep codes updated: Regenerate backup codes periodically
- Don't share codes: Never share your MFA codes or backup codes
