Enroll an authenticator app
When TFA is optional, the customer signs in and opens My Account > Two-Factor Authentication or uses the account dashboard action. With mandatory TFA, Magento opens the same setup after the password check and completes the login only after enrollment succeeds.

Complete setup
- Open the TFA setup page.
- Scan the QR code with a TOTP-compatible authenticator app. If scanning is unavailable, enter the displayed secret manually.
- Enter the current six-digit code from the app.
- Submit the form before the configured setup-secret lifetime expires.
- Save the recovery codes shown on the success page.
The issuer comes from configuration and the authenticator entry is labelled with the customer's email address.
Store the recovery codes
Recovery codes are shown in plain text only immediately after enrollment or regeneration. The customer can print them or download a text file. Returning to the dashboard shows only how many codes remain, not their values.
Each code works once. Store the set in a password manager or another protected location separate from the authenticator device. Do not send recovery codes through an unprotected support ticket.
If setup expires
An expired setup secret is rejected even if the authenticator displays a code for it. Reload setup, scan the newly generated QR code and use the code from the new authenticator entry. Remove the abandoned entry from the app to avoid confusion.