Multi-Mode MFA

Multi-Mode MFA

Introduction 

Multi-mode MFA is an option wherein you can enable more than one MFA mode for your Zoho account. Zoho provides four modes to choose from: OneAuth, SMS-based OTP, app-based OTP (authenticator apps), and Security key. To enable multi-mode MFA, you will need to configure at least two MFA modes

How to use multi-mode MFA  

If your primary mode isn't readily available when you're signing in to your account, you can use any of the other MFA modes you've enabled to sign in.

If you have enabled OneAuth as your primary mode: 

  1. Go to Zoho Accounts.
  2. Enter your email address, then click NEXT.
  3. Enter the password, then click SIGN IN.
    InfoIf you've enabled password-less sign-in, click Sign in another way directly.
  4. Click Sign in another way, then click Problem signing in?.
    1. If you have access to your mobile device, choose a corresponding MFA mode to sign in. 
    2. If you don't have access to your mobile device: 
      1. Click Can't access your mobile device?.
      2. Choose the option that applies to your case. 

If you have enabled SMS-based OTP/app-based OTP/Security key as your primary mode: 

NotesNote: For users who signed up after January 1, 2024, SMS-based OTP won't be provided as an MFA option. This is due to the susceptibility of SMS-based OTP  to various security threats like phishing, SS7, and SIM swapping attacks. Learn more
  1. Go to Zoho Accounts.
  2. Enter your email address, then click NEXT.
  3. Enter the password, then click SIGN IN.
  4. Click Problem signing in?.
    1. If you have access to your mobile device, choose a corresponding MFA mode to sign in.
    2. If you don't have access to your mobile device: 
      1. Click Can't access your mobile device?.
      2. Choose the option that applies to your case.

How to delete a specific MFA mode  

  1. Sign in to your Zoho account.
  2. Click Multi-Factor Authentication.
  3. Click next to the MFA mode you want to delete, then click Confirm.
InfoRefer our help guide in case you wish to disable MFA for your account.