Multi-Factor Authentication
What is Multi-Factor Authentication?
Multi-Factor Authentication (MFA) provides an additional layer of security when logging in to your Cloud account.
Normally, you log in using your username and password. With MFA enabled, you must also confirm your identity using a second method. This means that even if somebody obtains your password, they should not be able to access your account without also completing the additional verification step.
MFA is one of the most effective ways of protecting accounts against unauthorised access resulting from stolen, guessed or compromised passwords.
MFA on our Cloud framework
MFA becomes mandatory for all users of our Cloud framework from 1 October 2026.
MFA is available now and can be enabled before this date. We recommend early adoption so that users can become familiar with the login process before MFA becomes compulsory.
Once MFA is enabled, after entering your username and password, you will be asked to complete an additional verification step before access is granted.
Available verification methods
Cloud framework supports two MFA methods:
- Email Verification using a One-Time Passcode (OTP)
- Authenticator App
Email Verification using OTP
When Email Verification is used, a six-digit OTP is sent to your registered email address.
Enter the OTP when prompted to complete your login.
Each OTP:
- is valid for 10 minutes from the time it is generated;
- can be used once only; and
- becomes invalid after it has been successfully used or its 10-minute validity period has expired.
If you request or receive more than one OTP, any OTP may be used, provided that it is still within its individual 10-minute validity period and has not already been used. Requesting a new OTP does not automatically invalidate an earlier OTP that is still valid.
You should never give an OTP to another person. Our support team will never ask you to tell them your OTP.
Authenticator App
An Authenticator App generates a temporary verification code on your smartphone or other compatible device. After entering your username and password, enter the current code displayed by the app when prompted.
Authenticator Apps do not normally require an email or text message to be delivered each time you log in, making this method both convenient and less dependent on email availability.
A range of standard authenticator applications can be used, including commonly available apps such as Microsoft Authenticator and Google Authenticator.
Which method should I use?
Where practical, we recommend using an Authenticator App as your normal MFA method. It provides a convenient verification method without relying on access to your email account.
Email Verification is a straightforward alternative method where use of an Authenticator App is not practical.
You can configure both methods on our Cloud framework and use either one each time you log in.
Whichever method you use, MFA significantly improves the security of your Cloud account compared with relying on username and password alone.
When will I need to set up MFA?
You can enable MFA now and begin using it immediately.
From 1 October 2026, MFA will be mandatory for users of our Cloud framework and users will be required to complete MFA verification as part of the login process.
We therefore recommend that you enable MFA in advance rather than waiting until the mandatory introduction date.