Find answers to common MFA questions, including verification code errors, authentication failures, device replacement, and enforcing or disabling MFA.
Verification code error during MFA binding
-
MFA is time-based. Ensure the time on your mobile device is synchronized.
-
MFA codes refresh every 30 seconds. Enter the latest unused code.
-
The QR code (key) can expire if the binding page stays open too long. Refresh the page and scan a new QR code.
-
Scanning the QR code multiple times may create duplicate entries on your MFA device, each with a different code. This can cause authentication to fail. Delete any duplicates before scanning a new QR code.
-
Rebind the MFA device. Steps vary by account type:
-
Rebind the MFA device for an Alibaba Cloud account.
-
Unbind the MFA device.
-
Rebind the MFA device.
-
-
Rebind the MFA device for a RAM user.
If the Alibaba Cloud account owner allows RAM users to manage their own MFA devices, the RAM user can unbind and rebind independently. Otherwise, contact the account owner or a RAM administrator.
-
Unbind the MFA device.
-
Rebind the MFA device.
-
-
-
If the issue persists, submit a ticket. Include screenshots of the error page, your device's displayed time, the account name, and the operation timestamp.
MFA authentication failure during sign-in
-
MFA is time-based. Ensure the time on your mobile device is synchronized.
-
Verify that you entered the latest unused code for the correct account.
-
If you replaced the MFA device, use the code from the newly bound device.
-
Rebind the MFA device. Steps vary by account type:
-
Rebind the MFA device for an Alibaba Cloud account.
-
Unbind the MFA device.
-
Rebind the MFA device.
-
-
Rebind the MFA device for a RAM user.
If the Alibaba Cloud account owner allows RAM users to manage their own MFA devices, the RAM user can unbind and rebind independently. Otherwise, contact the account owner or a RAM administrator.
-
Unbind the MFA device.
-
Rebind the MFA device.
-
-
-
If the issue persists, submit a ticket. Include screenshots of your device's displayed time, the authenticated account name, and the operation timestamp.
Authenticator app deleted or device lost
-
Alibaba Cloud account: Submit an appeal from the identity verification page.
-
RAM user: Contact the account owner or a RAM administrator to disable MFA. How do I disable MFA for a RAM user's console sign-in?.
Replace an MFA device
To replace the MFA device for an Alibaba Cloud account or a RAM user, for example when moving the authenticator app to a new phone, follow these steps.
Replace MFA device for an Alibaba Cloud account
-
Log on to the Account Center.
-
Unbind the MFA device on Phone A.
-
Rebind the MFA device on Phone B.
Replace MFA device for a RAM user
If the Alibaba Cloud account owner allows RAM users to manage their own MFA devices, the RAM user can unbind and rebind independently. Otherwise, contact the account owner or a RAM administrator. Manage security settings for RAM users.
-
Log on to the RAM console.
-
Unbind the MFA device on Phone A.
-
Rebind the MFA device on Phone B.
Enforce MFA for RAM user sign-in
An Alibaba Cloud account owner or RAM administrator can enforce MFA for RAM users through user security settings and console logon settings.
-
Require all RAM users to use MFA
In the user security settings, set MFA for RAM user sign-in to Force all users. Manage security settings for RAM users.
-
Require specific RAM users to use MFA
-
In the user security settings, set MFA for RAM user sign-in to Depend on each user.
-
In the console logon settings for the RAM user, set MFA Required to Required.
Create a RAM user or Manage console logon settings for a RAM user.
-
After these settings take effect, RAM users must bind an MFA device at their next sign-in. After binding, they must enter a verification code for all subsequent sign-ins. Bind an MFA device as a RAM user.
Disable MFA for RAM user sign-in
Disabling MFA reduces account security. Assess the security risks of password compromise before disabling MFA.
To better protect your account and assets, this feature will be gradually rolled out by account UID starting March 28, 2025. RAM users with the AdministratorAccess system permission must use MFA for sign-in. MFA cannot be disabled for these users. Notice.
Unbinding an MFA device is not the same as disabling MFA. To disable MFA for console sign-in, you must modify both user security settings and console logon settings.
-
Modify user security settings for the RAM user.
In the user security settings, set MFA for RAM user sign-in to Depend on each user or Required Only for Unusual Logon. Manage security settings for RAM users.
-
Depend on each user: MFA is configured per user. Proceed to the next step.
-
Required Only for Unusual Logon: MFA is enforced only in untrusted sign-in environments, such as when the sign-in location or device changes. Otherwise, MFA is not required.
-
-
Modify console logon settings for the RAM user.
In the console logon settings for the RAM user, set MFA Required to Not Required. Manage console logon settings for a RAM user.