> For the complete documentation index, see [llms.txt](https://docs.ggwp.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.ggwp.com/identity-and-access-management-iam/mfa.md).

# MFA

## Overview

* GGWP Dashboard supports Multi-Factor Authentication (MFA) to enhance the security of your account. MFA adds an extra layer of protection by requiring not just a password but also a second form of verification.
* Enabling MFA ensures that even if a password or SSO login is compromised, unauthorized users still cannot access the dashboard.
* MFA is enabled at the organization level, which may have multiple games (tenants) under it. Once enabled, all dashboard users must **enroll and use** MFA when logging in.

## Login Flow with MFA Enabled

When enabled, MFA require users to:

* Login via credentials or SSO as usual
* Provide a secondary authentication code generated via the registered authenticator app

## Enabling/Disabling MFA

* Please let your GGWP account manager know if you'd like to enable or disable MFA for your organization.

## MFA Registration Flow

A one-time registration is required for all dashboard users once MFA is enabled.

* When you log in for the first time after MFA is enabled, you'll see this screen:

<figure><img src="/files/Yt7Q8XU5hvnw2vCj9JHJ" alt=""><figcaption></figcaption></figure>

* Scan the QR code using any TOTP supported app (e.g., Duo Mobile, Google Authenticator, Authy, etc). This generates a unique, time-based code that refreshes every 30-60 seconds.
* Enter the code from the app on the screen.
* You'll see a recovery code displayed on the next screen - make sure to copy and store it securely. This recovery code can be used once in case you lose access to the TOTP app.<br>

  <figure><img src="/files/QZVmZKKj7cb1tv1879qT" alt=""><figcaption></figcaption></figure>

That's it! MFA setup is complete!

When logging in moving forward, the GGWP dashboard will prompt you to enter a new code each time from your registered authenticator app.

## Resetting a User's MFA

If a user loses access to their authenticator app and cannot log in to the GGWP dashboard, an admin can reset that user's MFA by following these steps:

* Navigate to the `Manage Users (Global)` page on the dashboard.
* Click the three dot menu icon on the right hand side of the corresponding user entry.
* Click on the Reset MFA option from this menu. Once reset, the user will need to follow the [MFA Registration Flow](#mfa-registration-flow) again to set up the secondary auth freshly. \ <br>

  <figure><img src="/files/Unpm19ALe8R4wWXrqsWt" alt=""><figcaption></figcaption></figure>
