Why turn it on
A password is a single point of failure. People reuse them, share them and fall for phishing. Multi-factor authentication (MFA) requires something you know (your password) plus something you have (a code from your phone or authenticator app), so one leaked credential isn't enough to get in.
Set it up
You enable MFA from your account security settings. Have your phone and an authenticator app ready before you start.
Open your security settings
Go to your account settings and find the multi-factor authentication option. Your overall account is described in your profile.
Add a factor
Scan the on-screen code with your authenticator app, which then generates a rotating one-time code.
Confirm the code
Enter the current code from your app to prove the link works and activate MFA.
Save your recovery codes
Store the recovery codes somewhere safe and offline. They let you back in if you lose your device.
Signing in with MFA on
After MFA is enabled, signing in takes one extra step: enter your password, then the current code from your authenticator app. The code changes every few seconds, so an old code won't work.
- Keep your device's clock accurate — authenticator codes are time-based.
- If a code is rejected, wait for the next one and try again.
- Never share a code with anyone, including someone claiming to be support.
If you lose your device
Losing your phone shouldn't lock you out permanently. That's what your recovery codes are for.
- Use a saved recovery code to sign in, then re-add MFA on your new device.
- If you've lost both your device and your recovery codes, you'll need to verify your identity with us.
- See login and access issues for the recovery path, or contact support.
MFA for teams
Encourage everyone who can edit, approve or send documents to enable MFA. Combined with right-sized roles, it limits the damage a single compromised account can do.
Set roles and access deliberately — see team members and roles and permissions. MFA on accounts plus least-privilege roles is a strong baseline.