Authenticator App - Novaz

Malwarebytes Nebula 2FA Setup Guide

cloud.malwarebytes.com SupportedChecked against official help · September 25, 2026

Your Nebula login opens the console where you deploy and manage endpoint protection for your organization. Since May 20, 2026, two-factor authentication (2FA) has been mandatory for all Nebula users: if you haven't set it up, Nebula prompts you before you can sign in. It uses an authenticator app on a mobile device, so Authenticator App - Novaz can provide your codes.

A Malwarebytes Nebula account is part of your security setup, so it deserves strong 2FA of its own. Malwarebytes Nebula secures sign-ins with an authenticator app — set it up once and you're protected on every login.

2FA methods Malwarebytes Nebula supports

  • Authenticator app (TOTP)

Before you start

  • Your Nebula email address and password. New users first click "Verify" in the "Verify your ThreatDown Request" email and create a password
  • An iPhone or iPad with a camera and Authenticator App - Novaz installed, because Nebula needs a mobile device with a camera and an authenticator app
  • The Nebula login page (cloud.threatdown.com/auth/login) open on a computer, so the QR code is on a different screen from your phone
  • If your organization signs in through SAML 2.0 single sign-on (for example Okta or Azure AD), SSO already satisfies the 2FA requirement
  • For Super Admins: a second Super Admin account, which ThreatDown recommends so one can reset 2FA for the other

Part 1: Turn on 2FA in Malwarebytes Nebula

  1. 1

    Sign in to Nebula

    On the Nebula login page, enter your email address and click "Next", then enter your password and click "Log In".

  2. 2

    Open the 2FA setup screen

    Nebula shows "Two-factor authentication must be configured for your user account." with a QR code on the right. You must finish this before you can use the console.

Part 2: Add Malwarebytes Nebula to Authenticator App - Novaz

  1. 3

    Scan the QR code in Authenticator App - Novaz

    Open Authenticator App - Novaz, tap the + button and scan the QR code. If it won't scan, click "here" under "Unable to scan the QR code?" to get a key. Choose to enter a setup key in the app and type it in. Check the account name, then tap "Save".

  2. 4

    Note the code

    Authenticator App - Novaz now shows a code for Nebula. It changes every 30 seconds, so enter it before it expires.

Part 3: Confirm and finish

  1. 5

    Enter the code

    Back in Nebula, type the code into the box under "Enter the code from your authenticator app." When Nebula accepts it, you'll see "Your two-factor authentication set up was successfully verified" and the console opens.

  2. 6

    Add a recovery email if asked

    If a Super Admin has turned on recovery codes by email, Nebula asks you for a recovery email address when you log in. It must be on a different domain from your Nebula login email. You can set or change it later under your display name > "Profile" > "Security".

If something goes wrong

  • "Code is incorrect or expired": codes change every 30 seconds. Make sure your iPhone sets its date and time automatically (Settings > General > Date & Time), then enter the most recent code.
  • "Session timed out": the time on the computer you log in with must match the time on your phone. Sync the computer's time settings, then log in again.
  • You're switching phones or apps and are still logged in: click your display name > "Profile", go to the "Security" tab and click "Reset Settings", then set up Authenticator App - Novaz again.
  • You still can't log in: ask another Super Admin to reset your 2FA, or contact ThreatDown Support.

How to recover your Malwarebytes Nebula account

ThreatDown's Nebula help doesn't describe backup codes. Email recovery codes only work if a Super Admin turned on "Allow the recovery code to be sent via email" (under "Configure" > "Users" > "Two-factor authentication") before you need one, and you've set a recovery email. In that case, on the Nebula login page, enter your email address and password, click "Try another way", then "Send". Enter the recovery code from the email on the verification screen and click "Submit". ThreatDown notes that this setting could let someone who gets into your email bypass 2FA. Otherwise, another Super Admin can go to "Configure" > "Users", click "Reset" next to your name and confirm with "Reset 2FA". If no other Super Admin is available, contact Support.

Frequently asked questions

Can I skip 2FA in Nebula?
No. The prompt could be skipped only during the May 7–19, 2026 transition. Since May 20, 2026, any user who hasn't enrolled must do so before accessing the console. Only SAML 2.0 single sign-on is an alternative.
Which authenticator apps does Nebula support?
ThreatDown lists Google Authenticator, Authy, 1Password, Microsoft Authenticator, Okta Verify, Duo Mobile and LastPass Authenticator. Authenticator App - Novaz isn't named, but you add Nebula to it the same way, by scanning the QR code on the setup screen.
How do I reset 2FA for another user?
As a Super Admin, go to "Configure" > "Users", click "Reset" next to the user and click "Reset 2FA" in the confirmation window.

Generate your Malwarebytes Nebula codes in Authenticator App - Novaz

Free, offline, and encrypted. One tap for every 6-digit code.

Get the app

More Security guides

Novaz is not affiliated with, endorsed by, or sponsored by Malwarebytes Nebula. Malwarebytes Nebula and its logo are trademarks of their respective owner and are used here for identification only.