Skip to main content

Multi-Factor Authentication

Multi-factor authentication (MFA) adds a second step when you sign in, so that knowing your password alone is not enough to access your account. In the Gallium Console each user manages MFA on their own account, and Gallium provides MFA directly: for native Gallium accounts, your second factor is handled by Gallium rather than delegated to an outside provider.

This page walks you through adding MFA methods, turning MFA on, and signing in once it's enabled.

Before You Begin

You manage MFA from your own account in the Gallium Console. Open the profile menu using the avatar at the top right, choose User Settings, and then select the MFA tab.

The key rule to know up front is that you must add at least two MFA methods before you can turn MFA on. Setting up two methods gives you a fallback if one becomes unavailable: for example, if you lose access to your authenticator app, you can still sign in with a recovery code or YubiKey. Plan to set up a couple of methods in one sitting so you can enable MFA at the end.

note

Accounts managed through Single Sign-On do not manage MFA in Gallium. For those accounts, authentication is governed by your identity provider, so the MFA tab does not apply.

Adding an MFA Method

You add methods one at a time from the MFA tab. Under Your Authenticators, click Add MFA Method to start. Every method asks you for a Description: a label you choose so you can recognize the method later (for example, "Phone authenticator" or "Office YubiKey").

Gallium supports three method types, described in the sections below. Add whichever combination suits you, keeping in mind that you'll need at least two before you can enable MFA.

Authenticator App (TOTP)

A time-based one-time password (TOTP) app generates a short code that changes every few seconds. This is a common, convenient second factor that works with most authenticator apps on your phone.

  1. Click Add MFA Method and enter a Description.
  2. Choose TOTP. A Setup and Confirm TOTP screen appears showing a QR code.
  3. Scan the QR code with your authenticator app.
  4. Enter the Code generated by the app.
  5. Click Complete Setup.

You see MFA Method Added to confirm the authenticator is registered.

YubiKey

A YubiKey is a physical hardware key that produces a one-time code when you touch it. If you have one, you can register it as a second factor.

  1. Click Add MFA Method and enter a Description.
  2. Choose Yubikey.
  3. Click into the Yubikey OTP field and press the YubiKey button to capture its code.
  4. Continue to finish registering the key.

A success screen confirms the method was added.

Recovery Codes

Recovery codes are single-use backup codes you can fall back on if your other methods aren't available. To add them, click Add MFA Method, enter a Description, and choose Recovery Codes. Gallium then generates a set of codes for you.

warning

Recovery codes are shown only once and are single-use. Save them somewhere safe before closing the window. They cannot be retrieved afterward.

Enabling MFA

Once two or more methods exist on your account, the Enable MFA button becomes active. Until then it stays disabled, so if you don't see it light up, go back and add another method.

  1. On the MFA tab, confirm you have at least two methods listed under Your Authenticators.
  2. Click Enable MFA.

You see MFA Enabled, and the status changes to Enabled with the message Your account is protected.

Signing In with MFA

With MFA enabled, signing in takes one extra step. After you enter your email and password, you're prompted for a Multi Factor Code. Enter the current code from your authenticator (or the code from another registered method) to complete sign-in.

Removing a Method

You can remove a method you no longer use from the Your Authenticators table. Find the method, click its delete (trash) icon, and confirm when prompted.

Requiring MFA Across Your Organization

MFA is set up by each user on their own account, and there is no self-service setting to require it for everyone in an organization. If your organization needs MFA enforced for all members, contact Gallium support. See Getting Help.