Multi-Factor Authentication
Multi-factor authentication (MFA) adds a second step when you sign in, so knowing your password alone is not enough to reach your account. Each user sets MFA up on their own account.
You manage MFA from your profile: open the profile menu using the avatar at the top right and choose User Settings. The Your Authenticators card lists your registered methods, and a banner above it shows whether MFA is on.
You need two methods before you can turn MFA on. The second is your fallback if the first becomes unavailable.
Accounts managed through Single Sign-On do not use Gallium’s MFA. Their authentication is governed by the identity provider.
Add an MFA Method
On the Your Authenticators card, click Add MFA Method. Choose a type under Select Type, enter a Description so you can recognize the method later, and click Next. What follows depends on the type you chose.
Authenticator App (TOTP)
A time-based one-time password app generates a code that changes every few seconds, which makes it the most convenient of the three.
Choosing TOTP opens a Setup and Confirm TOTP screen showing a QR code. Scan it with your authenticator app, enter the generated Code, and click Complete Setup.
YubiKey
A YubiKey is a hardware key that produces a one-time code when you touch it.
Choosing Yubikey adds a Yubikey OTP field alongside the description. Click into it and press the key’s button to capture a code.
Recovery Codes
Recovery codes are single-use backup codes for when your other methods are not available.
Gallium generates eight of them and shows them once. The Type column tracks how many you have left. There is no way to regenerate a set: add a new one and remove the old.
Recovery codes are shown only once. Save them somewhere safe before closing the window. They cannot be retrieved afterward.
Enable MFA
Once you have two methods, an Enable MFA button appears in the banner above Your Authenticators. Below two methods there is no button, and the banner reads Add two authenticators before you can enable multi-factor authentication.
Click Enable MFA. The banner turns green and reads MFA Enabled, Your account is protected.
Sign In with MFA
With MFA on, signing in asks for a Multi Factor Code after your password. The same prompt appears when you reset your password.
Remove a Method
On the Your Authenticators card, click the delete icon on the method’s row and confirm. Remove Authenticator warns that the method can no longer complete a sign-in, and that the removal cannot be undone.
While MFA is enabled you must keep at least two methods. Removing one that would leave you with fewer is refused.
Contact Support to Disable or Enforce MFA
Two things cannot be done from the Console:
- Turning MFA off. Once it is enabled, there is no self-service way to disable it on your account.
- Requiring MFA for everyone. There is no organization-wide setting that enforces MFA for all members.
For either, contact Gallium support. See Getting Help.