AlibabaCloud 2FA: How to Set Up an Authenticator App
Your Alibaba Cloud account controls your cloud resources and billing, so a password alone is thin protection. Alibaba Cloud supports authenticator apps that follow the TOTP standard through its "Account Protection" setting, where multi-factor authentication (MFA) is now called Time-based One-time Password (TOTP). Authenticator App - Novaz can generate the 6-digit codes.
A AlibabaCloud account can hold your files and backups of everything else, so protect it with 2FA. AlibabaCloud secures sign-ins with an authenticator app — set it up once and you're protected on every login.
2FA methods AlibabaCloud supports
- Authenticator app (TOTP)
Before you start
- Your Alibaba Cloud account logon details (RAM users bind a device differently, see the FAQ)
- Access to the email address or mobile phone number on your account, because Alibaba Cloud verifies your identity before showing the QR code
- Authenticator App - Novaz installed on your iPhone or iPad
- The Account Center open on a computer, so the QR code is on a different screen from your phone
Part 1: Turn on 2FA in AlibabaCloud
- 1
Open Security Settings
Log on to the Alibaba Cloud Account Center with your Alibaba Cloud account and go to the "Security Settings" page.
- 2
Set up Account Protection
In the "Other Settings" section, click "Set up" next to "Account Protection". Alibaba Cloud's beginner guide shows this button as "Edit"; once protection is on, it reads "Modify".
- 3
Choose scenarios and TOTP
On the "Enable Account Protection" page, select one or more protection scenarios (when Alibaba Cloud will ask for a code) and TOTP as the verification method. Click "OK".
- 4
Verify your identity
Verify your identity by email address or mobile phone number. With email, Alibaba Cloud sends a 6-digit code: enter it and click "OK". Then click "Next" to open the binding page with the QR code.
Part 2: Add AlibabaCloud to Authenticator App - Novaz
- 5
Scan the QR code with Authenticator App - Novaz
Open Authenticator App - Novaz, tap the + button and scan the QR code on the binding page. Check the account name, then tap "Save".
- 6
Note the 6-digit code
Authenticator App - Novaz now shows a 6-digit code for Alibaba Cloud. It changes every 30 seconds, so have it ready for the next step.
Part 3: Confirm and finish
- 7
Enter the code and click Next
Back in the Account Center, enter the 6-digit code and click "Next". Account Protection is now enabled with TOTP.
- 8
Know when you'll need a code
From now on you enter a code from Authenticator App - Novaz after your password when you log on to the console, and in the other scenarios you selected. To change scenarios, click "Modify" next to "Account Protection", then "Edit".
- 9
Save a way to recover your account
If AlibabaCloud offers backup or recovery codes, download them or write them down and store them somewhere safe. They are how you get back into your account if you ever lose your phone. If it doesn't, check how AlibabaCloud recovers accounts before you need it.
If something goes wrong
- Alibaba Cloud rejects the code: codes change every 30 seconds, so enter the newest one, and make sure your iPhone sets its date and time automatically (Settings > General > Date & Time).
- The emailed identity code doesn't work: it's valid for 15 minutes, so request a new one.
- You're changing phones or deleting the app: detach the virtual MFA device first, or you can't log on. Click "Modify" next to "Account Protection", click "Turn off" for the method, and verify with a code or "Try a different method".
- Turning protection off doesn't finish: if a security review starts, log on to the Account Center again and click "Approve" or "Confirm" on the detach request in your notifications or to-do items.
Checked against AlibabaCloud's own help pages on September 25, 2026. Menu names can change, so these pages have the current path:
- Attach or detach a virtual MFA device – Alibaba Cloud Documentation Center ↗
- Configure security settings for an Alibaba Cloud account – Alibaba Cloud Documentation Center ↗
- How to recover account access when MFA or IP restrictions block logon – Alibaba Cloud Documentation Center ↗
- Bind an MFA device for a RAM user – Alibaba Cloud Documentation Center ↗
How to recover your AlibabaCloud account
Alibaba Cloud's help doesn't describe backup codes for Account Protection, so the fallback is a manual appeal once you've checked no other MFA device or logon method works. Go to the Alibaba Cloud home page, click "Login", then "Other Sign In Difficulties?" at the bottom. Select "I cannot log in (MFA/TOTP and login mask could not be verified)" and click "Next step". Complete the slider verification, fill in the appeal form with an email address and mobile number you can reach, and click "Submit". You get a "Query code" to track progress, and a support engineer contacts you to verify your identity and payment information before detaching the device. Then set up TOTP again.
Frequently asked questions
- Is TOTP the same as Alibaba Cloud's MFA?
- Yes. Alibaba Cloud renamed MFA to Time-based One-time Password (TOTP). A virtual MFA device is any app that follows the TOTP standard (RFC 6238), so Authenticator App - Novaz works like the Alibaba Cloud app and Google Authenticator named in the docs.
- I'm a RAM user. Do I follow the same steps?
- No. Log on through the RAM user logon page, hover over your profile picture, click "Security Information", then click "Bind VMFA" next to "MFA Device" under "MFA Information". At your first logon you may instead be asked to select "Virtual MFA Device": Alibaba Cloud has been making MFA mandatory for RAM users since March 17, 2025.
- Can several people share codes for one account?
- Alibaba Cloud's docs suggest screenshotting the QR code during the first setup so other users can scan it and get the same codes. Keep that screenshot as safe as the password.
Generate your AlibabaCloud codes in Authenticator App - Novaz
Free, offline, and encrypted. One tap for every 6-digit code.
Get the appMore Cloud guides
Novaz is not affiliated with, endorsed by, or sponsored by AlibabaCloud. AlibabaCloud and its logo are trademarks of their respective owner and are used here for identification only.



