DocumentationAdministration

Account security and MFA

Enroll an authenticator and distinguish account security from workspace identity settings.

Updated 2026-09-22 Read as Markdown
On this page

Enroll an authenticator

Open Account → Security in the console. Start two-factor enrollment, scan the displayed QR code with your authenticator, then enter its code to verify enrollment. The enrollment secret is sensitive; do not include it in a screenshot, support request, or shared document.

The console updates the account profile after successful verification. Check the enabled state and verify the expected sign-in experience through your organization’s normal account procedure. The current screen does not provide a disable-MFA control.

Separate account and workspace controls

Account MFA protects the user’s authentication flow. Workspace membership, approval permission, environment keys, and device credentials have their own authority and lifecycle. A workspace’s enterprise SAML configuration is a separate integration.

Roles and environments · SAML and SCIM

Recover access deliberately

Follow your organization’s account recovery procedure or contact Kastra support if enrollment or sign-in is unavailable. Do not reset a workspace’s runtime credentials merely to work around an account sign-in problem. The security page also displays information about the current authenticated session; it is not a complete device-coverage report.

Verify before rollout

Check the MFA requirements actually enforced by the deployed server and your identity provider. UI wording alone does not establish a universal tenant policy. Device management · Contact support.