tencent cloud

About Account

MFA Device Overview

Download
포커스 모드
폰트 크기
마지막 업데이트 시간: 2026-08-13 16:28:17
AI 번역

Overview

Multi-Factor Authentication (MFA) is a simple and effective security authentication method. It adds another layer of account protection in addition to a username and password. An MFA device, also called a dynamic password card or token, is a device that provides this type of secure authentication method. Currently, Tencent Cloud supports two authentication methods: Virtual MFA Device and U2F Security Key.

Virtual MFA Device

A virtual MFA device is an application program that generates dynamic authentication codes. It is compliant with the time-based one-time password (TOTP) standard as defined in RFC 6238. Tencent Cloud's Virtual MFA device supports mainstream TOTP-compliant apps such as Google Authenticator and Microsoft Authenticator.
Attention:
You need to download the Google Authenticator App and Microsoft Authenticator App from your app store.

U2F Security Key

U2F, known as Universal 2nd Factor, represents an open standard designed to enhance the security of Multi-Factor Authentication (MFA). Formulated by the Fast Identity Online Alliance (FIDO), this alliance aims to improve the security of internet identity verification. Users can complete the multi-factor authentication process by plugging a U2F hardware device into the computer's USB port and tapping a button on the key.

Products That Support MFA Devices

The products that have MFA enabled and their corresponding operations are listed in the following table:

Computing

Supported Product
Supported Action
CVM
Binding a Key Pair
Querying the Instance Management Terminal Address
Adjusting the Instance Configuration
Shutting Down Instance
Rolling Back a Snapshot
Obtaining a VNC Login Token
Deleting a Snapshot
Deleting a Snapshot Policy
Terminating a Cloud Disk
Detaching a Cloud Disk
Modifying Instance VPC Attributes
Modifying the Instance Renewal Flag
Modifying the Cloud Disk Renewal Flag
Terminating an Instance
Instance restart
Reset Password
Reinstalling an Instance
Lighthouse
Terminating an instance.
Resetting an Application
Image
Creating an Image
Deleting an Image
ECM
Querying the Instance Management Terminal Address

Containers and Middleware

Supported Product
Supported Action
CloudBase
View keys from secure sources.
Creating custom login keys.
Freeze or unfreeze a postpaid resource.
Modifying database permissions.
Modifying SCF Configuration.
Deleting a Database Collection.
Deleting a Database Index
Modifying Storage Permissions.

Storage

Supported Product
Supported Action
Cloud File Storage
Updating a file system permission group
Updating a file system permission group rule
Deleting a Mount Point
Verify the deletion of file systems.
Deleting a File System Permission Group
Deleting a File System Permission Group Rule
Cloud Object Storage
Emptying a Bucket
Deleting a Bucket
Setting a Bucket ACL
Setting a Bucket Policy
Setting a Bucket Lifecycle Rule

Database

Supported Product
Supported Action
TDSQL for MySQL
Isolating a pay-as-you-go instance
Switch Network
Terminate a Pay-As-You-Go Instance
Terminate the exclusive instance
Terminate an isolated yearly/monthly subscription instance.
Account Deletion
Account Authorization
Change Account Password
MariaDB
Isolating a pay-as-you-go instance
Switch Network
Terminate a Pay-As-You-Go Instance
Terminate the exclusive instance
Terminate an isolated yearly/monthly subscription instance.
Account Deletion
Account Authorization
Change Account Password
Redis
Simulates faults.
Emptying a Redis Instance.
Modify Instance Sub-account
Reset Password
TencentDB for MySQL
Database Product MFA Verification Test Dedicated Identifier
Reset Account Password
Data Transfer Service
Isolate Subscription Instance.

Networking and CDN

Supported Product
Supported Action
VPC
Creating a Routing Policy.
Disabling Subnet Routing.
Enabling Subnet Routing.
Deleting a Routing Table
Deleting a Routing Policy
Replacing Routing Table Associations.
Replacing a Routing Policy.
CDN
Disabling CDN Service.
Delete domain names.
CLB
Deleting a CLB Instance
NAT Gateway
Deleting a NAT Gateway.
Deleting a Private NAT Gateway.

Media Services

Supported Product
Supported Action
VOD
Modify VOD service status.
Modify sub-application status.
TRTC
Delete TRTC application service.
Set TRTC application service status (enable/disable).

Security

Supported Product
Supported Action
Identity and Access Management Public Edition
Deleting user pools

AI

Supported Product
Supported Action
eKYC
Disable postpaid
OCR
OCR service configuration

IoT

Supported Product
Supported Action
IoT Explorer
Create Sensitive Operation Verification

Enterprise Applications and Cloud Communications

Supported Product
Supported Action
Domains
MFA-Verified Domain Name Transfer
Initiating a Push
Obtaining Transfer-Out Authorization Codes
Receiving a Push
Disabling the Update Lock
Disabling the Transfer Lock
Rejecting a Push
Batch Disabling of Domain Name Updates
Batch Disabling of Domain Name Transfers
Batch Modification of Domain Name DNS Information
Batch Modification of Domain Name Information
Batch Renewal of Domain Names
Batch Registration of Domain Names
Batch Transfer-in of Domain Names
Canceling a Transfer-Out
Deleting DNSSEC
Deleting a Custom DNS Host
Adding DNSSEC
Synchronizing DNSSEC
Modifying DNSSEC
Modifying a Custom DNS Host
Binding a Domain Name Template
Batch Transfer of Domain Names
HTTPDNS
Obtain the corresponding key or Token based on the ID.
Resetting a Key
DNSPod
Creating Keys
Creating a Domain Parking Page
Disabling DNSSEC
Restoring Domain Name Sharing
Enabling DNSSEC
Batch Adding of Records
Batch Adding of Domain Names
Batch Modification of Records
Canceling the Disabling of DNSSEC
Canceling the Enabling of DNSSEC
Confirming the Enabling of DNSSEC
Deleting PTR Reverse Resolution Records
Deleting Records
Deleting a Key
Delete domain names.
Deleting Domain Name Sharing
Deleting a Domain Name Parking Page
Uploading DNS Record Files
Setting DNS Record Status
Locking Domain Names
Adding Domain Name Sharing
Modifying DNS Records
Modifying a Key
Modifying the Domain Name Bound to a Plan
Modifying Domain Name Sharing
Modifying Domain Name Parking Status
Modifying a Domain Name Parking Page
Modifying Domain Name Status
Modifying Auto-renewal Status
One-click Modification of DNS Servers
Exporting Records in Excel File Format
Exporting Records in TXT File Format
Exporting Records in Zone File Format
Domain Name Transfer
Unlocking Domain Names
Pausing Domain Name Sharing
Instant Messaging
Disabling Legacy IM Editions
Deletes an application.
Disabling Applications

Industry Applications

Supported Product
Supported Action
Tencent Mobile Framework
App Cloud, obtain sensitive keys.

Developer Services

Supported Product
Supported Action
CAM
Binding Token
View API key plaintext.
Querying All User Groups.
Querying Project Keys.
Querying User Keys.
Processing Login Restriction Approvals.
Creating an Approval Assistant.
Creating a WeChat Sub-user Invitation QR Code.
Creating a Sub-user
Creating Sub-account Binding Restrictions.
Creating a Sub-account Login IP Policy.
Configuring Sensitive Operations for the International Site.
Obtaining a Temporary Token for MFA Verification.
Unbinding Token
Unbinding Soft Token
Unbinding Sub-user Login Methods
Unbinding Sub-account Token
Unbinding Sub-account Soft Token
Disabling an API Key.
Disabling Non-root Account API Keys.
Disabling Project Keys.
Enabling an API Key.
Enabling Non-root Account API Keys.
Enabling Project Keys.
Creating a Role in the Console.
Batch Creating Sub-users.
Batch Adding Sub-users.
Deleting an API Key.
Deleting Non-root Account API Keys.
Deleting Project Keys.
Deleting Sub-users
Configuring Security Protection.
Modifying Soft Token
Modifying Hard Token
User Analysis

Management and Support

Supported Product
Supported Action
Account
Bind MFA Token.
Bind WeChat.
View API key plaintext.
Query Current MFA Status.
Unbind MFA Token.
Unbind Registered Associated Account.
Set Identity Verification MFA Verified Flag.
Configure User Login Protection and Sensitive Operation Verification Methods.
Request Account Deletion.
Remove Login Session.
Modify User Phone Number.
Modify User Email.
Modify Email Password.
Modify Email Account Password.
Configure Security Settings for Remote Login
Associate Account with Mail.
Associate Account with WeChat.
Confirm Account Association.
Unbind Account Association.
Associate Account with WeChat Official Account.
Associate Account with WeCom Login Method.
Reset Email Login Password.
Finance
Confirm Bill.
Channel management
Pay on Behalf
Add Employee.
Transfer


도움말 및 지원

문제 해결에 도움이 되었나요?

피드백