MFA Management¶
Guance supports Multi-Factor Authentication (MFA) based on TOTP (Time-based One-Time Password), adding dynamic security code verification beyond account passwords to prevent unauthorized access caused by password leaks.
When a workspace enables the MFA Security Authentication mandatory policy, all members must complete MFA binding to enter that space. Even if the mandatory policy is not enabled, members can also bind MFA themselves to enhance account security.
Bind MFA¶
- In the Guance workspace, go to the User Settings > Security Settings page in the lower left corner.
- In the MFA Authentication section, click the Bind button on the right.
- Follow the guide to complete the following three-step verification.
Step 1: Identity Verification¶
The system sends a verification code to the registered email. Enter the code to confirm your identity.
Step 2: Configure Authenticator¶
Download and install an authenticator app on your phone (recommended: Google Authenticator, Microsoft Authenticator, or Alibaba Cloud App). Scan the QR code displayed on the page or manually enter the secret key to add the account.
After successful addition, the app will generate a 6-digit dynamic security code (refreshed every 30 seconds).
Step 3: Complete Binding¶
Enter the current 6-digit security code displayed by the app on the page, and click OK to complete the binding. After successful binding, the MFA Authentication status will show as "Bound".
After binding, the next time you log in, after entering your account password, the system will require you to enter the MFA security code. Open the authenticator app and enter the currently displayed 6-digit number to complete the login.
Workspace Mandatory Policy¶
Workspace owners can enable the MFA Security Authentication switch in Manage > Workspace Management > Security. After enabling:
- Bound members: Log in normally, unaffected.
- Unbound members: After logging in, they are forcibly directed to the binding page and must complete binding to enter the workspace.
- New members: Must bind MFA upon first login.
This policy applies to all members within the workspace (including administrators), with the exception of the owner only. If a member cannot bind due to special circumstances, they need to contact the owner for assistance.
Unbind MFA¶
Method 1¶
If you no longer need to use MFA authentication, you can unbind MFA for your account.
- On the MFA Authentication page, click the Unbind button on the right.
- Enter the dynamic code and click OK.
- After unbinding, the system will indicate "Not Bound".
Method 2¶
If during login, the device with the MFA authenticator is not available, preventing you from generating a security code to log in, you can contact Guance customer service to apply for unbinding.
- Click Help > Ticket Management below the navigation bar.
- After entering the ticket page, click "Submit Ticket".
- Select the ticket type as Unbind MFA.
- Fill in the ticket title, description, and email verification code, then submit the ticket.
Guance customer service will process your application as soon as possible after receiving it.
For more details, please refer to Ticket Management.







