---
sourceDocument: Xanadu Platform security
sourceDocumentLink: https://www.servicenow.com/docs/r/xanadu/platform-security

 Release :

    - xanadu

ft:locale :

    - en-US

ft:publication_title :

    - Xanadu Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Using Multi-factor authentication (MFA)

# Using Multi-factor authentication (MFA) {#ariaid-title1}

* Release version: Xanadu
* 
* Updated August 1, 2024
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Learn how to use multi-factor authentication tools to securely access your instance.

## Login with MFA {#mfa-use__section_pm3_k34_dpb}

ServiceNow requires authenticator applications that support Time-based One-time Passwords (TOTP). ServiceNow tests MFA with the following authenticators:

* Google Authenticator
* Microsoft Authenticator
* LastPass Authenticator
* Authy
* FreeOTP
* Duo
* Okta Verify

{#mfa-use__ul_dgx_rm3_zhb}  
Note:  
* Other authenticators not listed might also be compatible, but are not tested by ServiceNow.
* For information related to browser specific behavior change, see this [KB article](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB0998122)
{#mfa-use__ul_wxh_y2s_pcc}

|-|-|
| Validation with authenticator app <br /> <br /> Enter the code displayed on your authenticator app to login. | If your administrator has enabled multi-factor authentication (MFA) on your instance, you are prompted for a second authentication after entering your user name and password. For details on the MFA login process, see [Log in with multi-factor authentication](https://www.servicenow.com/docs/qCZt1FDAfLlqWYM0sDw4Zw "Login with multi-factor authentication when it is enabled by your administrator on your instance.") If you haven't configured a second form of authentication, you will see a configuration page after logging in to guide you through the process of setting up an authentication app. For details on this setup, see [Setup multi-factor authentication for the first time](https://www.servicenow.com/docs/9cG23MyTBRYm5Ggl0Ci2Jg "If your administrator enabled multi-factor authentication on your profile but you have not yet set up the application, you can set it up upon login."). |
[ ]

{#mfa-use__table_g22_2j4_dpb}

## Register an authentication device {#mfa-use__section_pyc_yj4_dpb}

|-|-|
| After you've configured an authentication app, you can register other methods for authentication. Biometric authenticators :   You can use biometric authenticators like fingerprint or facial recognition as your second MFA authentication. If your administrator allows this option, you can configure biometric authenticators using the steps in [Register a biometric authenticator](https://www.servicenow.com/docs/CITqzul8JsckOox_Fh2Log "Register a biometric authenticator to use as part of your multi-factor authentication login."). Hardware key authenticators :   Hardware keys are physical security devices you can use for authentication. You can register a hardware device for use with your instance using the steps in [Register a hardware security key](https://www.servicenow.com/docs/eDAI6WhJzb0ceVVMqVYrSA "Register a hardware key to use as part of your multi-factor authentication login."). | ![Hardware key icon]() |
| Validation with Biometric or Hardware Key <br /> <br /> | Use the Biometric or Security Key to login. |
[ ]

{#mfa-use__table_qm1_zj4_dpb}

## Register a phone number for OTP {#mfa-use__section_ilx_bwb_2vb}

|-|-|
| SMS :   Admin configures ServiceNow instance to require users who attempt to login the instance using SMS based OTP. When users attempt to login to ServiceNow, SMS OTP is sent to the mobile number associated with the sys_user record. Users can enter the six-digit verification code that it sent to the mobile device and verify their identity. | ![SMS.]() |
| Validation with SMS <br /> <br /> | Enter the 6-digit code sent to the mobile number to login. The code sent is valid for the next 5 minutes. You can use resend code to again send the code. |
[ ]

{#mfa-use__table_bjc_2wb_2vb}

## Register an Email address for OTP {#mfa-use__section_clt_zvb_2vb}

|-|-|
| Email address :   Admin configures ServiceNow instance to require users who attempt to login the instance using Email based OTP. When users attempt to login to ServiceNow, Email OTP is sent to the email address associated to the user. User's can enter the six-digit verification code that it sent to the mobile device and verify their identity. | ![Email.]() |
| Validation with Email <br /> <br /> | Enter the 6-digit code sent to the email address to login. The code sent is valid for the next 5 minutes. You can use resend code to again send the code. |
[ ]

{#mfa-use__table_xwx_dwb_2vb}

