Authenticator App - Novaz

IBM Cloud 2FA: How to Set Up an Authenticator App

cloud.ibm.com SupportedChecked against official help · September 25, 2026

Your IBM Cloud login gives access to every account you're a member of and all the resources in them, so a password alone isn't enough. IBM Cloud calls the feature multifactor authentication (MFA), and its time-based one-time passcode (TOTP) factor works with an authenticator app such as Authenticator App - Novaz.

A IBM Cloud account can hold your files and backups of everything else, so protect it with 2FA. Besides an authenticator app, IBM Cloud also offers email codes and security keys. An authenticator app (TOTP) is usually the best balance of security and convenience. For the strongest protection, IBM Cloud also supports hardware security keys.

2FA methods IBM Cloud supports

  • Email code
  • Security key (U2F / WebAuthn)
  • Authenticator app (TOTP)

Before you start

  • Your IBMid (or other IBM Cloud login) and password
  • MFA turned on in at least one IBM Cloud account you belong to, since factors are only used at login once an administrator enables MFA. For your own account, you can do this yourself (step 1)
  • At least two verification methods (email, text message or phone call): IBM Cloud asks for two every time you open the page where factors are managed. Text and voice work only in supported countries
  • Authenticator App - Novaz installed on your iPhone or iPad
  • The IBM Cloud console open on a computer, so the QR code is on a different screen from your phone

Part 1: Turn on 2FA in IBM Cloud

  1. 1

    Make sure MFA is required

    If you administer the account (IAM Identity Service or All IAM Account Management services), go to "Manage" > "Access (IAM)" > "Settings" in the IBM Cloud console, click "Authentication" and select a TOTP option, such as "MFA for users with an IBMid" or "TOTP MFA" under MFA for all users. This affects every member of the account. Otherwise, ask your administrator.

  2. 2

    Open Verification methods and authentication factors

    Go to the "Verification methods and authentication factors" page at iam.cloud.ibm.com/mysecurity. If MFA was just turned on, your next login walks you through the same checks.

  3. 3

    Verify your identity twice

    Choose two different verification methods. For each one, enter the one-time password (OTP) that IBM Cloud sends and click "Verify".

  4. 4

    Add a TOTP factor

    Click "Show authentication factors", then "Add". Select "TOTP" and enter a name that tells you which device it is, such as "Novaz iPhone". IBM Cloud shows a QR code.

Part 2: Add IBM Cloud to Authenticator App - Novaz

  1. 5

    Scan the QR code in Authenticator App - Novaz

    Open Authenticator App - Novaz, tap the + button and scan the QR code. Check the account name, then tap "Save".

  2. 6

    Note the passcode

    Authenticator App - Novaz now shows a time-based passcode for IBM Cloud that refreshes automatically. Have the current one ready for the next step.

Part 3: Confirm and finish

  1. 7

    Enter the code to finish

    Back on IBM Cloud, enter the code generated by Authenticator App - Novaz to finish adding the TOTP factor.

  2. 8

    Know when IBM Cloud will ask for a code

    IBMid asks for your additional factor once on each new device or browser. After you've used it there, you aren't prompted for it again on that device.

  3. 9

    Save a way to recover your account

    If IBM Cloud offers backup or recovery codes, download them or write them down and store them somewhere safe. They are how you get back into your account if you ever lose your phone. If it doesn't, check how IBM Cloud recovers accounts before you need it.

If something goes wrong

  • You see "Error: Incorrect validation code.": one of your factors may be inaccessible. Reset it as described under recovery below.
  • The code is refused right after setup: make sure your iPhone sets its date and time automatically (Settings > General > Date & Time), then enter the newest passcode.
  • An email OTP for verification doesn't arrive: check every folder in your mailbox, for example the Other folder in Outlook.
  • You're asked to enroll in MFA for an account you don't use: if any account you're a member of enables MFA, you must enroll at your next login.

How to recover your IBM Cloud account

IBM Cloud's docs don't describe backup codes. Instead, they tell you to add backup authentication factors and backup verification methods, so one lost device doesn't lock you out. If your phone is gone, open iam.cloud.ibm.com/mysecurity, validate your identity with two verification methods, click "Show accounts" and note each account's Authentication setting. For "MFA for All users", select the lost factor, click "Remove" and set up a new one at your next login. For "MFA for IBMid users", work with the IBMid help desk to reset your factors. If you can't use your verification methods either, open a support case to reset them.

Frequently asked questions

Which MFA factors does IBM Cloud offer?
Email-based MFA (level 1), TOTP from an authenticator app (level 2) and a hardware security key (level 3). You can always use a higher level than the one your account requires.
Can I turn on MFA for my own account without the IAM settings?
Yes. On the "Verification methods and authentication factors" page, click "Show accounts" > "Manage your own account". Changing it affects every member of that account.
Do API keys still work after MFA is enabled?
Yes. MFA applies to logins, not API calls, and API keys for users and service IDs keep working.

Generate your IBM Cloud codes in Authenticator App - Novaz

Free, offline, and encrypted. One tap for every 6-digit code.

Get the app

More Cloud guides

Novaz is not affiliated with, endorsed by, or sponsored by IBM Cloud. IBM Cloud and its logo are trademarks of their respective owner and are used here for identification only.