Malwarebytes Nebula 2FA Setup Guide
Your Nebula login opens the console where you deploy and manage endpoint protection for your organization. Since May 20, 2026, two-factor authentication (2FA) has been mandatory for all Nebula users: if you haven't set it up, Nebula prompts you before you can sign in. It uses an authenticator app on a mobile device, so Authenticator App - Novaz can provide your codes.
A Malwarebytes Nebula account is part of your security setup, so it deserves strong 2FA of its own. Malwarebytes Nebula secures sign-ins with an authenticator app — set it up once and you're protected on every login.
2FA methods Malwarebytes Nebula supports
- Authenticator app (TOTP)
Before you start
- Your Nebula email address and password. New users first click "Verify" in the "Verify your ThreatDown Request" email and create a password
- An iPhone or iPad with a camera and Authenticator App - Novaz installed, because Nebula needs a mobile device with a camera and an authenticator app
- The Nebula login page (cloud.threatdown.com/auth/login) open on a computer, so the QR code is on a different screen from your phone
- If your organization signs in through SAML 2.0 single sign-on (for example Okta or Azure AD), SSO already satisfies the 2FA requirement
- For Super Admins: a second Super Admin account, which ThreatDown recommends so one can reset 2FA for the other
Part 1: Turn on 2FA in Malwarebytes Nebula
- 1
Sign in to Nebula
On the Nebula login page, enter your email address and click "Next", then enter your password and click "Log In".
- 2
Open the 2FA setup screen
Nebula shows "Two-factor authentication must be configured for your user account." with a QR code on the right. You must finish this before you can use the console.
Part 2: Add Malwarebytes Nebula to Authenticator App - Novaz
- 3
Scan the QR code in Authenticator App - Novaz
Open Authenticator App - Novaz, tap the + button and scan the QR code. If it won't scan, click "here" under "Unable to scan the QR code?" to get a key. Choose to enter a setup key in the app and type it in. Check the account name, then tap "Save".
- 4
Note the code
Authenticator App - Novaz now shows a code for Nebula. It changes every 30 seconds, so enter it before it expires.
Part 3: Confirm and finish
- 5
Enter the code
Back in Nebula, type the code into the box under "Enter the code from your authenticator app." When Nebula accepts it, you'll see "Your two-factor authentication set up was successfully verified" and the console opens.
- 6
Add a recovery email if asked
If a Super Admin has turned on recovery codes by email, Nebula asks you for a recovery email address when you log in. It must be on a different domain from your Nebula login email. You can set or change it later under your display name > "Profile" > "Security".
If something goes wrong
- "Code is incorrect or expired": codes change every 30 seconds. Make sure your iPhone sets its date and time automatically (Settings > General > Date & Time), then enter the most recent code.
- "Session timed out": the time on the computer you log in with must match the time on your phone. Sync the computer's time settings, then log in again.
- You're switching phones or apps and are still logged in: click your display name > "Profile", go to the "Security" tab and click "Reset Settings", then set up Authenticator App - Novaz again.
- You still can't log in: ask another Super Admin to reset your 2FA, or contact ThreatDown Support.
Checked against Malwarebytes Nebula's own help pages on September 25, 2026. Menu names can change, so these pages have the current path:
- Two-factor authentication (2FA) settings in Nebula – ThreatDown Support Portal ↗
- Troubleshoot two-factor authentication (2FA) in Nebula – ThreatDown Support Portal ↗
- User profile settings in Nebula – ThreatDown Support Portal ↗
- Nebula Quick Start Guide – ThreatDown Support Portal ↗
- Nebula Release Notes - May 2026 – ThreatDown Support Portal ↗
How to recover your Malwarebytes Nebula account
ThreatDown's Nebula help doesn't describe backup codes. Email recovery codes only work if a Super Admin turned on "Allow the recovery code to be sent via email" (under "Configure" > "Users" > "Two-factor authentication") before you need one, and you've set a recovery email. In that case, on the Nebula login page, enter your email address and password, click "Try another way", then "Send". Enter the recovery code from the email on the verification screen and click "Submit". ThreatDown notes that this setting could let someone who gets into your email bypass 2FA. Otherwise, another Super Admin can go to "Configure" > "Users", click "Reset" next to your name and confirm with "Reset 2FA". If no other Super Admin is available, contact Support.
Frequently asked questions
- Can I skip 2FA in Nebula?
- No. The prompt could be skipped only during the May 7–19, 2026 transition. Since May 20, 2026, any user who hasn't enrolled must do so before accessing the console. Only SAML 2.0 single sign-on is an alternative.
- Which authenticator apps does Nebula support?
- ThreatDown lists Google Authenticator, Authy, 1Password, Microsoft Authenticator, Okta Verify, Duo Mobile and LastPass Authenticator. Authenticator App - Novaz isn't named, but you add Nebula to it the same way, by scanning the QR code on the setup screen.
- How do I reset 2FA for another user?
- As a Super Admin, go to "Configure" > "Users", click "Reset" next to the user and click "Reset 2FA" in the confirmation window.
Generate your Malwarebytes Nebula codes in Authenticator App - Novaz
Free, offline, and encrypted. One tap for every 6-digit code.
Get the appMore Security guides
Novaz is not affiliated with, endorsed by, or sponsored by Malwarebytes Nebula. Malwarebytes Nebula and its logo are trademarks of their respective owner and are used here for identification only.



