Title
Page icon
Create new category
Edit page index title
Edit category
Edit link
Sign In With Multi Factor Authentication
Explanation (Core Concepts)
What is Sign In with Multi-Factor Authentication?
Multi-Factor Authentication (MFA) requires a second proof of identity — beyond your password — before you can sign in to xDP. As a Governance & Security Administrator, you enable MFA so that a leaked or guessed password alone is not enough to access your tenant; every user then needs a code from a device they control in addition to their password. Once enabled, MFA applies to every user signing in, not just administrators.
xDP delegates authentication to Admin Central, the identity backend shared across the platform. MFA is enforced at that layer: xDP itself has no separate MFA toggle, because sign-in for every xDP capability already routes through Admin Central's login screen.
Key Concepts
Authenticator app — A time-based one-time password (TOTP) app on your phone or desktop that generates a new numeric code every 30 seconds; the standard second factor for xDP sign-in.
Enrollment — The one-time setup where you link an authenticator app to your account, typically by scanning a QR code shown during your first sign-in after MFA is enabled.
Verification code — The current code from your authenticator app, entered alongside your password on every subsequent sign-in.
Enforcement — The administrator setting that requires MFA for some or all users in a tenant, configured at the identity backend rather than per xDP feature.
Capabilities
Sign-in with MFA covers two moments in a user's session:
First-time enrollment (configuration) — A user sets up their authenticator app the first time they sign in after MFA is required.
Ongoing verification (monitoring) — Every subsequent sign-in prompts for a verification code alongside the password.
Tutorial (Getting Started)
Prerequisites
Your administrator has enabled MFA enforcement for your tenant in Admin Central.
You have a smartphone or desktop authenticator app installed and ready before your next sign-in.
Note: If MFA isn't enforced for your tenant yet, you'll sign in with just your password — the authenticator-app prompt only appears once your administrator turns enforcement on.
Your First Workflow
This walkthrough covers the one-time enrollment a user completes the first time they sign in after MFA is enabled.
Go to your xDP sign-in URL and enter your username and password as usual.
When prompted to set up multi-factor authentication, open your authenticator app (FreeOTP, Google Authenticator, or Microsoft Authenticator) and scan the QR code shown.
Enter the one-time code your authenticator app generates, optionally name the device, and submit to confirm enrollment.
Complete sign-in — you're now enrolled, and land in xDP as usual.
On every sign-in after enrollment:
Enter your username and password.
Enter the current one-time code from your authenticator app.
Sign in.
Example: A data analyst signs in to xDP each morning with their password, then a 6-digit code from their phone's authenticator app — so a phished password alone can't be used to reach their Trino queries.
How-to Guides
Recover access after losing your authenticator device
You already have MFA enrolled and lost or replaced the device holding your authenticator app.
Contact your Governance & Security Administrator — self-service re-enrollment typically requires an administrator to reset your MFA registration in Admin Central.
Once your MFA registration is reset, sign in with your password and complete first-time enrollment again on your new device.
Confirm you can sign in end-to-end with the new device's verification code.
Warning: Don't share verification codes with anyone, including support staff — a legitimate administrator resets your enrollment rather than asking for your current code.
Best Practices
Tip: Enforce MFA for all users, not just administrators — the highest-value accounts to protect are often the ones with the broadest data access, not just admin roles.
Enroll on a device you always have with you. A phone-based authenticator app is more reliable day-to-day than a desktop-only one.
Keep a backup enrollment path documented for your team. Losing the only enrolled device without a recovery process locks a user out until an administrator intervenes.
Never share a verification code, even with support. A code is only useful within its 30-second window — sharing it defeats the purpose of the second factor.
For additional help, contact our Support Team!
©2026, Acceldata Inc — All Rights Reserved.