Account security and MFA
Enroll an authenticator and distinguish account security from workspace identity settings.
On this page
Enroll an authenticator
Open Account → Security in the console. Start two-factor enrollment, scan the displayed QR code with your authenticator, then enter its code to verify enrollment. The enrollment secret is sensitive; do not include it in a screenshot, support request, or shared document.
The console updates the account profile after successful verification. Check the enabled state and verify the expected sign-in experience through your organization’s normal account procedure. The current screen does not provide a disable-MFA control.
Separate account and workspace controls
Account MFA protects the user’s authentication flow. Workspace membership, approval permission, environment keys, and device credentials have their own authority and lifecycle. A workspace’s enterprise SAML configuration is a separate integration.
Roles and environments · SAML and SCIM
Recover access deliberately
Follow your organization’s account recovery procedure or contact Kastra support if enrollment or sign-in is unavailable. Do not reset a workspace’s runtime credentials merely to work around an account sign-in problem. The security page also displays information about the current authenticated session; it is not a complete device-coverage report.
Verify before rollout
Check the MFA requirements actually enforced by the deployed server and your identity provider. UI wording alone does not establish a universal tenant policy. Device management · Contact support.