Elastic Cloud 2FA Setup with an Authenticator App
Your Elastic Cloud login opens your deployments and projects, and the same login is used for Elastic's Support Hub and Learning Portal. Elastic calls the feature multifactor authentication (MFA): it's mandatory when you log in with an email and password and can't be turned off. Its "Authenticator app" method uses time-based one-time passwords (TOTP), so Authenticator App - Novaz can generate your codes.
A Elastic Cloud account can hold your files and backups of everything else, so protect it with 2FA. Besides an authenticator app, Elastic Cloud also offers security keys and email codes. An authenticator app (TOTP) is usually the best balance of security and convenience. For the strongest protection, Elastic Cloud also supports hardware security keys.
2FA methods Elastic Cloud supports
- Authenticator app (TOTP)
- Security key (U2F / WebAuthn)
- Email code
Before you start
- Your Elastic Cloud email address and password. If you log in only with Google or Microsoft, or through SAML SSO, MFA is managed by that provider instead
- To add a password login to a Google or Microsoft account, use the "Forgot password" page (cloud.elastic.co/forgot); Elastic then prompts you to set up MFA when you log in
- Authenticator App - Novaz installed on your iPhone or iPad
- The Elastic Cloud Console open on a computer, so the QR code is on a different screen from your phone
Part 1: Turn on 2FA in Elastic Cloud
- 1
Log in to the Elastic Cloud Console
Log in at cloud.elastic.co with your email and password. If you haven't set up any MFA method yet, Elastic redirects you to an MFA setup screen, and you can only reach your service once at least one method is set up.
- 2
Open User settings > Profile
Go to "User settings" (cloud.elastic.co/user/settings) and choose "Profile". Scroll to the "Multifactor authentication" section.
- 3
Select Set up on the Authenticator app card
On the "Authenticator app" card, select "Set up". Elastic shows a QR code; keep the page open.
Part 2: Add Elastic Cloud to Authenticator App - Novaz
- 4
Add Elastic Cloud in Authenticator App - Novaz
Open Authenticator App - Novaz, tap the + button and scan the QR code. If you can't scan it, Elastic lets you enter the code manually: choose to enter a setup key in the app and type it exactly as shown. Use "Elastic Cloud" as the account name, then tap "Save".
Part 3: Confirm and finish
- 5
Enter the code and enable the method
Back in Elastic Cloud, enter the verification code currently shown in Authenticator App - Novaz and select "Enable authentication method".
- 6
Add a second method
Elastic recommends at least two different methods, so losing one doesn't lock you out. In the same section, select "Set up" on the "Email" card (a code sent to your email address) or the "Security key or biometrics" card.
- 7
Know when Elastic asks for a code
For now, Elastic asks for an MFA challenge on every login through Elastic Cloud, including support.elastic.co and learn.elastic.co. In Kibana, it applies when you choose "Log in with Elastic Cloud", not "Log in with Elasticsearch".
- 8
Save a way to recover your account
If Elastic Cloud offers backup or recovery codes, download them or write them down and store them somewhere safe. They are how you get back into your account if you ever lose your phone. If it doesn't, check how Elastic Cloud recovers accounts before you need it.
If something goes wrong
- Elastic rejects the code: make sure your iPhone sets its date and time automatically (Settings > General > Date & Time), then enter the newest code.
- You can't configure MFA in Elastic Cloud: if you log in only with Google or Microsoft, manage MFA in that account's security settings, or add a password login first.
- You're looking for SMS: Elastic no longer lets you configure SMS as an MFA method, and SMS users are being moved to a different method.
- You can't remove a method: Elastic requires another method to be set up before you select "Remove".
Checked against Elastic Cloud's own help pages on September 25, 2026. Menu names can change, so these pages have the current path:
How to recover your Elastic Cloud account
Elastic's documentation doesn't describe backup or recovery codes, so your safety net is a second MFA method. Set up the "Email" method or a security key alongside Authenticator App - Novaz, as Elastic recommends, and you can still log in if your phone is lost. Only one email address can be used for MFA codes; to change it, update your account email address. If you can't use any of your configured methods, for example because your device is lost or stolen, contact Elastic support.
Frequently asked questions
- Can I turn off MFA for Elastic Cloud?
- No. MFA is mandatory when you log in with an email and password and can't be turned off. You can add methods, or remove one once another is set up.
- Which MFA methods does Elastic Cloud support?
- An authenticator app that generates TOTP codes, such as Authenticator App - Novaz; a hardware security key or biometrics, such as a YubiKey or fingerprint reader; and codes sent by email. SMS can no longer be configured.
- Does MFA apply when I log in to Kibana or Elasticsearch directly?
- No. It doesn't apply when you select "Log in with Elasticsearch" on the Kibana login screen or connect to an Elasticsearch endpoint. It does apply when you use "Log in with Elastic Cloud".
- My team shares one Elastic Cloud login. What should we do?
- Elastic recommends one account per person, invited to your organization as members, so each person can set up their own MFA.
Generate your Elastic Cloud codes in Authenticator App - Novaz
Free, offline, and encrypted. One tap for every 6-digit code.
Get the appMore Cloud guides
Novaz is not affiliated with, endorsed by, or sponsored by Elastic Cloud. Elastic Cloud and its logo are trademarks of their respective owner and are used here for identification only.


