# Two-factor authentication (/en/docs/platform/account/mfa)



Password, two-factor, and passkeys are managed under **Account**.

## Change your password [#change-your-password]

Go to **Password** > **Change password**, then enter the new password.

## Set up two-factor authentication [#set-up-two-factor-authentication]

**Two-factor authentication** > **Set up**. You scan a QR code with an authenticator app and confirm a code.

CentralCSP supports authenticator apps only. There is no SMS option and no recovery-code flow, so enrol a second device or keep the authenticator secret somewhere safe. Losing your only device means asking an administrator to get you back in.

## Remove two-factor [#remove-two-factor]

**Remove** asks for a fresh code before deleting the credential. That is intentional: someone with a borrowed session cannot strip your second factor.

<Callout type="warn" title="A workspace can require two-factor">
  If any workspace you belong to has **Require two-factor authentication** turned on, removing yours locks you out of that workspace until you enrol again. Your other workspaces are unaffected.
</Callout>

## Passkeys [#passkeys]

**Passkeys** > **Add passkey** registers your device, password manager, or security key for passwordless sign-in.

Passkeys can be added here but not listed or removed. Worth knowing before you register a device you are about to replace.

## When a workspace requires two-factor [#when-a-workspace-requires-two-factor]

Workspace admins can require it for everyone. If you belong to such a workspace without two-factor authentication enrolled, you cannot use it until you enrol, and you keep normal access to your other workspaces.

Enrolling once covers every workspace. For more information, refer to [Workspace security](/en/docs/platform/security/mfa).

## Next steps [#next-steps]

* [Profile](/en/docs/platform/account/profile)
* [Workspace security](/en/docs/platform/security/mfa)
