Enabling Multi-Factor Authentication (MFA)
Two-factor authentication (2FA) adds an extra layer of security to your LiteSOC account. This guide shows you how to enable and manage MFA.
Why Enable MFA?
- 🔒 Protect against password breaches
- 🛡️ Required for SOC 2 compliance
- ✅ Industry security best practice
- 🚫 Prevents unauthorized access even if password is compromised
Supported Methods
LiteSOC supports TOTP (Time-based One-Time Password) authenticator apps:
- Google Authenticator (iOS/Android)
- Authy (iOS/Android/Desktop)
- 1Password (built-in)
- Microsoft Authenticator
- Any TOTP-compatible app
Enabling MFA
Step 1: Access Security Settings
- Log in to your LiteSOC Dashboard
- Click your profile in the top right
- Go to Settings → Security
Step 2: Enable Two-Factor Authentication
- Find the Two-Factor Authentication section
- Click Enable 2FA
- Enter your password to confirm
Step 3: Scan the QR Code
- Open your authenticator app
- Tap Add Account or the + button
- Choose Scan QR Code
- Point your camera at the QR code on screen
Can't scan? Click "Enter code manually" and type the secret key.
Step 4: Verify Setup
- Enter the 6-digit code shown in your authenticator
- Click Verify
- 2FA is now enabled!
Step 5: Save Recovery Codes
Critical step! You'll be shown 10 recovery codes:
- Click Download or Copy
- Store them securely (password manager, safe, etc.)
- These codes let you log in if you lose your phone
Using MFA to Log In
After enabling MFA, your login flow becomes:
Email → Password → 6-digit code from app → Dashboard
Managing MFA
Regenerate Recovery Codes
- Go to Settings → Security
- Click Regenerate Recovery Codes
- Old codes are immediately invalidated
- Save your new codes securely
Disable MFA
- Go to Settings → Security
- Click Disable 2FA
- Enter your password and a valid 2FA code
- Confirm the action
⚠️ Disabling MFA reduces your account security. Only do this temporarily if switching devices.
Best Practices
- Use a reputable authenticator - Avoid SMS-based 2FA
- Backup your codes - Store recovery codes offline
- Enable on all accounts - Use 2FA everywhere you can
- Use app backup features - Authy and others support encrypted backup
Lost access to your authenticator? Use a recovery code or contact support.