Two-factor authentication (2FA) adds a critical layer of security to your Data Mammoth account. With 2FA enabled, logging in requires both your password and a verification code from an authenticator app — so even if your password is compromised, your account remains protected.
Why Enable 2FA?
- Protection against password theft — Stolen passwords alone cannot grant access.
- Defense against phishing — Even if you accidentally enter your password on a fake site, the attacker cannot log in without the second factor.
- Industry best practice — 2FA is recommended for all accounts that manage infrastructure and sensitive data.
- Compliance — Many security standards require multi-factor authentication for administrative access.
Prerequisites
You will need an authenticator app installed on your smartphone:
- Google Authenticator (iOS / Android)
- Authy (iOS / Android / Desktop)
- Microsoft Authenticator (iOS / Android)
- 1Password (built-in authenticator)
- Bitwarden (built-in authenticator)
How to Enable 2FA
Step 1 — Navigate to Security Settings
Step 2 — Start 2FA Setup
Step 3 — Scan the QR Code
If you cannot scan the QR code, click Enter manually and type the secret key into your authenticator app.
Step 4 — Enter the Verification Code
Step 5 — Save Backup Codes
After verification, you will be presented with a set of backup codes (also called recovery codes).
Important: Save these codes immediately in a secure location.
- Download the codes as a file.
- Print them and store in a safe place.
- Save them in a password manager.
Step 6 — Confirm Setup
2FA is now active on your account. The next time you log in, you will be prompted for both your password and a verification code.
Logging In with 2FA
Managing 2FA
Changing Your 2FA Device
If you get a new phone or want to switch authenticator apps:
Disabling 2FA
If you need to disable 2FA temporarily:
We strongly recommend keeping 2FA enabled at all times. Only disable it if absolutely necessary, and re-enable it immediately afterward.
Lost Access to 2FA
If you cannot access your authenticator app:
Use a Backup Code
Contact Support
If you have no backup codes:
2FA Best Practices
What to Do Next
- SSH Key Best Practices — Secure server access.
- Security at Data Mammoth — Our security overview.
- Locked Out of 2FA — Recovery Steps — Recovery guide.
- Complete Server Security Checklist — Full security review.