Add a second check to your M7 Identity sign-ins

A person shows a phone with a checkmark to a blue and amber robot at a sunlit desk.

Your authenticator app can now be part of your M7 sign-in. Personal M7 accounts can add two-factor authentication (2FA) and choose where M7 asks for a code. For local password sign-ins, that adds another proof before sign-in completes.

The method is TOTP, short for time-based one-time password. Your authenticator app creates a fresh six-digit code every 30 seconds. That code confirms that you have access to the app when M7 asks for it. It is a practical extra step for someone signing in to a work app with an M7 account.

Link an app, then choose the checks

Getting started takes only a few steps. Visit M7 two-factor settings while signed in, choose to link an authenticator, then scan the QR code with your preferred authenticator app. If scanning is not convenient, you can enter the setup key manually. Finally, enter a current six-digit code to confirm the link. Scanning alone does not finish enrollment, so keep the app open until M7 confirms it.

Linking an authenticator and deciding when to ask for it are deliberately separate. After setup, you can independently turn on a code requirement for local M7 password sign-ins, local-password Device Code approval, and using an already open M7 account for a new authorization. For the last option, choose the rhythm that fits you: every time, or once per 15 minutes, hour, or eight hours. Reuse within an interval stays tied to the same account and browser session. The sign-in guide explains these checks in full.

M7 handles the extra check

That means you can begin with password sign-ins, see how the flow feels, and then add the other checks when they suit your routine. An app that uses M7 Identity keeps its normal OpenID Connect flow, including Authorization Code with PKCE or Device Authorization. M7 presents the factor prompt itself; the app should never ask you for an M7 setup key, authenticator code, or recovery code.

Prepare for recovery

Set aside a moment for recovery, too. After confirming with your authenticator, you can generate ten recovery codes. Store them somewhere safe: they are shown once, and generating a replacement set invalidates the older set. A single unused code can stand in for the authenticator at a hosted second-factor prompt. The recovery screen has Disable two-factor authentication selected by default; using recovery with that option selected removes the authenticator and turns the checks off. Using the final unused recovery code also removes the authenticator. The account-management guide has the complete enrollment, recovery, and unlink instructions.

2FA is optional, and it gives you control over the places where you want an additional check. Open your M7 two-factor settings to link an authenticator and choose the checks that work for you.