How to enable 2FA on Drupal.org
Drupal.org supports app-based two-factor authentication (2FA). Turning it on adds a second layer of protection, so a stolen password alone can't unlock your Drupal.org account.
Step-by-step setup
- 1
Sign in to Drupal.org and open your Drupal.org account security settings.
- 2
Turn on two-factor authentication and choose the authenticator-app option.
Look for "Authenticator app", "Authentication app", or "TOTP" rather than SMS.
- 3
Scan the QR code with MS Authenticator App.
Open MS Authenticator App, tap add, and point your camera at the QR code Drupal.org displays. Can't scan? Enter the setup key manually instead.
- 4
Enter the 6-digit code to confirm.
Type the code MS Authenticator App generates to verify and link your Drupal.org account.
- 5
Save your backup codes.
Store the recovery codes Drupal.org gives you somewhere safe — you'll need them if you lose your phone.
Menu names on Drupal.org can change — the official Drupal.org 2FA documentation ↗ always has the exact, current path.
Frequently asked questions
- Does Drupal.org work with authenticator apps like MS Authenticator App?
- Yes. Drupal.org supports TOTP authenticator apps, so you can generate its two-factor codes in MS Authenticator App.
- Is Drupal.org two-factor authentication free?
- Yes. Enabling authenticator-app 2FA on Drupal.org is free — you only need the free MS Authenticator App.
- What if I lose access to my Drupal.org 2FA codes?
- Use the backup or recovery codes you saved during setup. If you didn't save them, contact Drupal.org support to regain access, then re-add the account to MS Authenticator App.
Generate your Drupal.org codes in MS Authenticator App
Free, offline, and encrypted. One tap for every 6-digit code.
Get the appMore Developer guides
Novaz is not affiliated with, endorsed by, or sponsored by Drupal.org. Drupal.org and its logo are trademarks of their respective owner and are used here for identification only.