# Account security and MFA

Enroll an authenticator and distinguish account security from workspace identity settings.

Updated: 2026-09-22

Canonical: https://docs.kastra.ai/admin/account-security

## Enroll an authenticator

Open Account → Security in the console. Start two-factor enrollment, scan the displayed QR code with your authenticator, then enter its code to verify enrollment. The enrollment secret is sensitive; do not include it in a screenshot, support request, or shared document.

The console updates the account profile after successful verification. Check the enabled state and verify the expected sign-in experience through your organization's normal account procedure. The current screen does not provide a disable-MFA control.

## Separate account and workspace controls

Account MFA protects the user's authentication flow. Workspace membership, approval permission, environment keys, and device credentials have their own authority and lifecycle. A workspace's enterprise SAML configuration is a separate integration.

[Roles and environments](https://docs.kastra.ai/admin/workspaces) · [SAML and SCIM](https://docs.kastra.ai/admin/sso-scim)

## Recover access deliberately

Follow your organization's account recovery procedure or contact Kastra support if enrollment or sign-in is unavailable. Do not reset a workspace's runtime credentials merely to work around an account sign-in problem. The security page also displays information about the current authenticated session; it is not a complete device-coverage report.

## Verify before rollout

Check the MFA requirements actually enforced by the deployed server and your identity provider. UI wording alone does not establish a universal tenant policy. [Device management](https://docs.kastra.ai/admin/devices) · [Contact support](https://kastra.ai/contact).
