Oracle Cloud Infrastructure 2FA Setup Guide
Your Oracle Cloud Infrastructure (OCI) sign-in opens the Console for your tenancy's cloud resources, so a second factor matters. OCI calls the feature 2-step verification (multifactor authentication, or MFA, for administrators), and its "Mobile App Passcode" factor works with any authenticator app that follows the TOTP standard, including Authenticator App - Novaz.
A Oracle Cloud Infrastructure account can hold your files and backups of everything else, so protect it with 2FA. Besides an authenticator app, Oracle Cloud Infrastructure also offers a proprietary app, SMS text codes, phone-call codes, email codes and security keys. An authenticator app (TOTP) is usually the best balance of security and convenience — and it's safer than SMS codes, which can be intercepted through SIM-swap attacks. For the strongest protection, Oracle Cloud Infrastructure also supports hardware security keys.
2FA methods Oracle Cloud Infrastructure supports
- Authenticator app (TOTP)
- Proprietary app
- SMS text message
- Phone call
- Email code
- Security key (U2F / WebAuthn)
Before you start
- Your OCI Console username and password (if you don't know how to reach the Console, the link is in your Welcome email)
- The mobile app factor enabled by your identity domain administrator; otherwise the option, or the whole "Security" tab, won't appear
- Authenticator App - Novaz installed on your iPhone or iPad
- The OCI Console open on a computer, and a secure place to store a bypass code
Part 1: Turn on 2FA in Oracle Cloud Infrastructure
- 1
Open User settings
Sign in to the OCI Console on your computer. In the navigation menu, select the Profile menu and then select "User settings".
- 2
Configure the mobile app on the Security tab
Select the "Security" tab. In the "2-step verification" section, under "Mobile app", select "Configure". The Console shows an authentication QR code.
- 3
Choose another authenticator app
On the "Mobile application" page, select the "Offline mode or use another authenticator app" checkbox; this is the option for third-party apps. To see the key as text, select "Enter key manually". Leave the Console open.
Part 2: Add Oracle Cloud Infrastructure to Authenticator App - Novaz
- 4
Add OCI in Authenticator App - Novaz
Open Authenticator App - Novaz and tap the + button. Scan the QR code, or choose to enter a setup key and type the key exactly as the Console shows it. Use your OCI username (usually your email address) as the account name, then tap "Save".
- 5
Note the passcode
Authenticator App - Novaz now shows a one-time passcode for OCI. It changes regularly, so have it ready for the next step.
Part 3: Confirm and finish
- 6
Enter the passcode and select Verify
Back on the "Mobile application" page in the Console, enter the passcode and select "Verify". The "Mobile app" tile now appears on the Security tab.
- 7
Generate a bypass code
On the same "Security" tab, under "Bypass codes", select "Generate". Store the code somewhere secure, for example written in a notebook, then select "Close".
- 8
Sign in with a passcode
At your next sign-in, the 2-Step Verification page appears after your username and password. Enter the code from Authenticator App - Novaz in the "Passcode" box and select "Verify".
- 9
Save a way to recover your account
If Oracle Cloud Infrastructure offers backup or recovery codes, download them or write them down and store them somewhere safe. They are how you get back into your account if you ever lose your phone. If it doesn't, check how Oracle Cloud Infrastructure recovers accounts before you need it.
If something goes wrong
- OCI rejects the passcode: OCI allows at most 90 seconds of clock difference, so make sure your iPhone sets its date and time automatically (Settings > General > Date & Time), then enter the newest code.
- There's no "Security" tab or no "Mobile app" option: your identity domain administrator hasn't enabled account recovery and MFA, or the mobile app factor. Ask your administrator.
- OCI waits for an app notification instead of asking for a passcode: select "Show alternative login methods" and choose the mobile app passcode. Push notifications only work in Oracle Mobile Authenticator.
- You sign in often from your own computer: if your administrator allows it, select "Trust this computer" when you enter the passcode to skip the code there for a set number of days.
Checked against Oracle Cloud Infrastructure's own help pages on September 25, 2026. Menu names can change, so these pages have the current path:
- Managing 2-Step Verification – Oracle Cloud Infrastructure Documentation ↗
- Using Mobile Authenticator Apps with MFA – Oracle Cloud Infrastructure Documentation ↗
- Adding an Account to the OMA App by Entering the Key Manually – Oracle Cloud Infrastructure Documentation ↗
- Generating a Bypass Code – Oracle Cloud Infrastructure Documentation ↗
- Using the Oracle Mobile Authenticator – Oracle Cloud Infrastructure Documentation ↗
How to recover your Oracle Cloud Infrastructure account
OCI lets you generate your own bypass codes once you're enrolled in 2-step verification: go to "User settings" > "Security" and select "Generate" under "Bypass codes". User-generated bypass codes never expire, but each works only once. If you lose the phone with Authenticator App - Novaz, select "Show alternative login methods" on the 2-Step Verification page and use a bypass code or another method you've set up. If you have no other method, or have lost your bypass code, contact your administrator or Oracle support to have a bypass code generated for you.
Frequently asked questions
- Do I have to use Oracle Mobile Authenticator?
- No. OCI works with any third-party authenticator app that follows the TOTP standard, with no special administrator setup. Oracle recommends its own app because it supports push notifications, which only work there, and extra security features.
- What if OCI asks me to enroll when I sign in?
- Users usually enroll the first time they sign in. Select "Mobile App" as the method, then choose "Enter Key Manually" or "Offline Mode or Use Another Authenticator App" and add the key to Authenticator App - Novaz as in the steps above.
- Which 2-step verification methods can I use?
- Whatever your identity domain administrator has enabled. OCI supports mobile app passcodes and notifications, text message (SMS) or phone call, email, security questions, FIDO devices such as a YubiKey or Touch ID, Duo Security and bypass codes.
Generate your Oracle Cloud Infrastructure codes in Authenticator App - Novaz
Free, offline, and encrypted. One tap for every 6-digit code.
Get the appMore Cloud guides
Novaz is not affiliated with, endorsed by, or sponsored by Oracle Cloud Infrastructure. Oracle Cloud Infrastructure and its logo are trademarks of their respective owner and are used here for identification only.


