---
sourceDocument: Yokohama Platform security
sourceDocumentLink: https://www.servicenow.com/docs/r/yokohama/platform-security

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Using MFA

# Using Multi-factor authentication {#ariaid-title1}

* Release version: Yokohama
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Using Multi-factor Authentication

Multi-factor authentication (MFA) enhances security for accessing your ServiceNow instance by requiring an additional verification step beyond your username and password.
This process can involve various authenticator applications and methods, ensuring that only authorized users gain access to your account.
Show full answer Show less  

## Key Features

* **Authenticator Apps:** ServiceNow supports Time-based One-time Passwords (TOTP) through various authenticator applications such as Google Authenticator, Microsoft Authenticator, LastPass Authenticator, Authy, FreeOTP, Duo, and Okta Verify.
* **Second Factor Authentication:** After entering your credentials, you will need to provide a code from your authenticator app. If MFA is not set up, you will be guided through the configuration process.
* **Biometric Authentication:** If enabled by your administrator, you can use fingerprint or facial recognition as an additional authentication method.
* **Hardware Key Authenticators:** Physical security devices can be registered for authentication, providing a secure login option.
* **SMS and Email OTP:** You can register a mobile number or email address to receive One-time Passwords (OTP) for verification during login, with a validation code that is valid for 5 minutes.

## Key Outcomes

By implementing MFA, you secure your ServiceNow instance against unauthorized access, significantly reducing the risk of account compromise. Users benefit from a streamlined login process while ensuring their data remains protected through multiple layers of authentication. This ultimately leads to enhanced security posture for your organization.  
Learn how to use multi-factor authentication tools to securely access your instance.

## Login with MFA {#mfa-use__section_pm3_k34_dpb}

ServiceNow requires authenticator applications that support Time-based One-time Passwords (TOTP). ServiceNow tests MFA with the following authenticators:

* Google Authenticator
* Microsoft Authenticator
* LastPass Authenticator
* Authy
* FreeOTP
* Duo
* Okta Verify

{#mfa-use__ul_dgx_rm3_zhb}  
Note:  
* Other authenticators not listed might also be compatible, but are not tested by ServiceNow.
* For information related to browser specific behavior change, see this [KB article](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB0998122).
{#mfa-use__ul_wxh_y2s_pcc}

## Register an authentication app {#mfa-use__section_arv_vms_3dc}

|-|-|
| Authenticator App :   You can use authenticator apps to use a second factor of authentication. | If your administrator has enabled multi-factor authentication (MFA) on your instance, you are prompted for a second authentication after entering your user name and password. For details on the MFA login process, see [Log in with multi-factor authentication](https://www.servicenow.com/docs/Q_osllsBeUBgiOvNH1H6dg "Login with multi-factor authentication when it is enabled by your administrator on your instance."). |
| Validation with Authenticator app :   Enter the code displayed on your authenticator app to login. | If you haven't configured a second form of authentication, you will see a configuration page after logging in to guide you through the process of setting up an authentication app. For details on this setup, see [Set up Multi-factor authentication for the first time](https://www.servicenow.com/docs/RxYMce243TUz4djjHnnu6w "If your administrator enabled MFA on your profile but you have not yet set up the application, you can set it up upon login."). |
[ ]

{#mfa-use__table_g22_2j4_dpb}

## Register an authentication device {#mfa-use__section_pyc_yj4_dpb}

|-|-|
| After you've configured an authentication app, you can register other methods for authentication. Biometric authenticators :   You can use biometric authenticators like fingerprint or facial recognition as your second MFA authentication. If your administrator allows this option, you can configure biometric authenticators using the steps in [Register a biometric authenticator](https://www.servicenow.com/docs/oKIqVG02MemoIDyE3K2AKw "Register a biometric authenticator to use as part of your multi-factor authentication login."). |   |
| Hardware key authenticators :   Hardware keys are physical security devices you can use for authentication. You can register a hardware device for use with your instance using the steps in [Register a hardware security key](https://www.servicenow.com/docs/PDOy7z60gLqgpsWLtHeGxA "Register a hardware key to use as part of your multi-factor authentication login."). | ![Hardware key icon]() |
| Validation with Biometric or Hardware Key :   Use the biometric or hardware key to login. | Use the Biometric or Security Key to login. |
[ ]

{#mfa-use__table_qm1_zj4_dpb}

## Register a phone number for OTP {#mfa-use__section_ilx_bwb_2vb}

|-|-|
| SMS :   Use SMS based OTP to require users who attempt to login. | When users attempt to login to ServiceNow, SMS OTP is sent to the mobile number associated with the sys_user record. Users can enter the six-digit verification code that it sent to the mobile device and verify their identity. <br /> ![SMS.]() |
| Validation with SMS :   Use the validation with SMS to login based on the OTP generated. | You need to enter the 6-digit code sent to the mobile number to login. The code sent is valid for the next 5 minutes. You can use resend code to again send the code. |
[ ]

{#mfa-use__table_bjc_2wb_2vb}

## Register an Email address for OTP {#mfa-use__section_clt_zvb_2vb}

|-|-|
| Email address :   Use Email based OTP to require users who attempt to login. | When users attempt to login to ServiceNow, Email OTP is sent to the email address associated to the user. User's can enter the six-digit verification code that it sent to the mobile device and verify their identity. <br /> ![Email.]() |
| Validation with Email :   Use the validation with Email to login based on the OTP generated. | You need to enter the 6-digit code sent to the email address to login. The code sent is valid for the next 5 minutes. You can use resend code to again send the code. |
[ ]

{#mfa-use__table_xwx_dwb_2vb}

