> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://knowledge.yourwatchtower.com/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# Multi Factor Authentication

# Multi-Factor Authentication

Multi-factor authentication (MFA), also called two-factor authentication (2FA), adds an extra layer of protection to your Watchtower account. After completing your primary sign-in, you verify your identity with a one-time code from an authenticator app or a text message.

Watchtower recommends using an **authenticator app** when possible. Unlike SMS codes, authenticator codes do not depend on cellular service and are less vulnerable to phone-number takeover attacks.

> 🗒️ Your organization may require MFA for all members. When MFA is required, you must set up a verification method before continuing. Depending on your organization's security policy, Watchtower may request MFA after password, magic-link, Google, Microsoft, or single sign-on authentication.

## Available Verification Methods

Watchtower supports two MFA methods:

* **Authenticator App (recommended):** Use a compatible authenticator app to generate a new six-digit, time-based code.
* **Text Message (SMS):** Receive a six-digit verification code at the phone number connected to your account.

You can enable both methods. If both are enabled, Watchtower lets you choose which one to use when signing in.

## Setting Up an Authenticator App

Before you begin, install an authenticator app on a device you control. Examples include Google Authenticator, Microsoft Authenticator, and Authy.

To connect the app to Watchtower:

1. Sign in at [app.yourwatchtower.com](https://app.yourwatchtower.com/).
2. Select your profile icon in the upper-right corner, then select **Profile**.
3. Find **Multi-Factor Authentication** under **My Account Security**.
4. Select **Set Up** next to **Authenticator App**.
5. Select **Get Started**.
6. In your authenticator app, scan the QR code shown by Watchtower. If you cannot scan it, manually enter the setup key displayed below the QR code.
7. Enter the six-digit code generated by the app. Watchtower verifies the code and enables the authenticator app for your account.
8. Save the recovery codes shown after setup. Each recovery code can be used only once. Store them somewhere secure and separate from the device running your authenticator app.

> ⚠️ Save your recovery codes before closing the setup window. You can print, copy, or download them during setup. If you regenerate the codes, previously generated codes stop working.

## Setting Up SMS

To receive MFA codes by text message:

1. Sign in at [app.yourwatchtower.com](https://app.yourwatchtower.com/).
2. Select your profile icon in the upper-right corner, then select **Profile**.
3. Find **Multi-Factor Authentication** under **My Account Security**.
4. Select **Set Up** next to **SMS**.
5. Enter the mobile phone number you want to use and select **Send Verification Code**.
6. Enter the six-digit code sent to your phone. Watchtower verifies the code and enables SMS for your account.

## Using MFA When You Sign In

After completing your primary sign-in:

1. If both authenticator-app and SMS verification are enabled, choose a verification method.
2. Enter the six-digit code from your authenticator app or text message.
3. After the code is verified, Watchtower signs you in.

Authenticator codes refresh automatically after a short time. SMS codes can be resent from the verification screen.

## Managing MFA

Open **Profile → My Account Security → Multi-Factor Authentication** to review your active methods or set up another available method.

If your organization does not require MFA, you can use the MFA switch to disable it. If your organization requires MFA for all members, you cannot disable MFA from your profile.

## Troubleshooting

### My authenticator code is not working

* Confirm that you are entering the code for your Watchtower account.
* Wait for the app to generate a new code, then try again.
* Make sure the date and time on your device are set automatically. Authenticator codes depend on an accurate device clock.
* If both methods are enabled, select **Use a different method** and verify by SMS.

### I did not receive an SMS code

* Confirm that the phone number connected to your account is correct.
* Select the option to resend the code and use the newest message you receive.
* Confirm that your phone has cellular service and can receive text messages.
* If messages still do not arrive, contact your mobile service provider.

### I lost access to my authenticator app

If SMS is also enabled, select **Use a different method** when signing in. Otherwise, contact Watchtower Support for assistance.

### My organization requires MFA

When an Admin requires MFA for all members, Watchtower prompts members without an enrolled method to set up an authenticator app or SMS during sign-in. Members cannot disable MFA while this policy is active.

## Need Help?

If you cannot access an enrolled verification method or continue to have trouble signing in, contact Watchtower Support.
