All Products
Search
Document Center

Resource Access Management:Multi-factor authentication (MFA) FAQ

Last Updated:Jul 10, 2026

Find answers to common MFA questions, including verification code errors, authentication failures, device replacement, and enforcing or disabling MFA.

Verification code error during MFA binding

  • MFA is time-based. Ensure the time on your mobile device is synchronized.

  • MFA codes refresh every 30 seconds. Enter the latest unused code.

  • The QR code (key) can expire if the binding page stays open too long. Refresh the page and scan a new QR code.

  • Scanning the QR code multiple times may create duplicate entries on your MFA device, each with a different code. This can cause authentication to fail. Delete any duplicates before scanning a new QR code.

  • Rebind the MFA device. Steps vary by account type:

  • If the issue persists, submit a ticket. Include screenshots of the error page, your device's displayed time, the account name, and the operation timestamp.

MFA authentication failure during sign-in

  • MFA is time-based. Ensure the time on your mobile device is synchronized.

  • Verify that you entered the latest unused code for the correct account.

  • If you replaced the MFA device, use the code from the newly bound device.

  • Rebind the MFA device. Steps vary by account type:

  • If the issue persists, submit a ticket. Include screenshots of your device's displayed time, the authenticated account name, and the operation timestamp.

Authenticator app deleted or device lost

Replace an MFA device

To replace the MFA device for an Alibaba Cloud account or a RAM user, for example when moving the authenticator app to a new phone, follow these steps.

Replace MFA device for an Alibaba Cloud account

  1. Log on to the Account Center.

  2. Unbind the MFA device on Phone A.

    Unbind a U2F security key.

  3. Rebind the MFA device on Phone B.

    Bind or unbind a U2F security key.

Replace MFA device for a RAM user

If the Alibaba Cloud account owner allows RAM users to manage their own MFA devices, the RAM user can unbind and rebind independently. Otherwise, contact the account owner or a RAM administrator. Manage security settings for RAM users.

  1. Log on to the RAM console.

  2. Unbind the MFA device on Phone A.

    Unbind an MFA device for a RAM user.

  3. Rebind the MFA device on Phone B.

    Bind an MFA device as a RAM user.

Enforce MFA for RAM user sign-in

An Alibaba Cloud account owner or RAM administrator can enforce MFA for RAM users through user security settings and console logon settings.

After these settings take effect, RAM users must bind an MFA device at their next sign-in. After binding, they must enter a verification code for all subsequent sign-ins. Bind an MFA device as a RAM user.

Disable MFA for RAM user sign-in

Disabling MFA reduces account security. Assess the security risks of password compromise before disabling MFA.

Note

To better protect your account and assets, this feature will be gradually rolled out by account UID starting March 28, 2025. RAM users with the AdministratorAccess system permission must use MFA for sign-in. MFA cannot be disabled for these users. Notice.

Unbinding an MFA device is not the same as disabling MFA. To disable MFA for console sign-in, you must modify both user security settings and console logon settings.

  1. Modify user security settings for the RAM user.

    In the user security settings, set MFA for RAM user sign-in to Depend on each user or Required Only for Unusual Logon. Manage security settings for RAM users.

    • Depend on each user: MFA is configured per user. Proceed to the next step.

    • Required Only for Unusual Logon: MFA is enforced only in untrusted sign-in environments, such as when the sign-in location or device changes. Otherwise, MFA is not required.

  2. Modify console logon settings for the RAM user.

    In the console logon settings for the RAM user, set MFA Required to Not Required. Manage console logon settings for a RAM user.