> For the complete documentation index, see [llms.txt](https://enterprise-ipi-en.hideez.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://enterprise-ipi-en.hideez.com/ipi-enterprise-server/administration/how-to-enable-two-factor-authentication-at-ipi-enterprise-server.md).

# How to enable two-factor authentication at the IPI Enterprise Server?

{% hint style="info" %}
This guide explains how to enable two-factor OTP (One-Time Password) authentication for accessing the IPI Enterprise Server (IES) web interface. To enable OTP for other websites, you must configure the appropriate settings on those sites.
{% endhint %}

***

### **Enabling 2FA for Admin Accounts**

#### **Step 1:**

In the top-right corner of the window, click on the **profile icon** and select **Profile** from the drop-down list.

<figure><img src="/files/rtHP0bxEDc1AMFyXrK5I" alt=""><figcaption></figcaption></figure>

#### **Step 2:**

In the Profile section, go to **One-Time Password** and click on the **Add OTP App** button.

<figure><img src="/files/AH9yIc807mwaf3Aj6sPi" alt=""><figcaption></figcaption></figure>

#### **Step 3:**

Follow the on-screen instructions to set up 2FA.

<div><figure><img src="/files/DOzKuvwrSvK4zPqSzqNC" alt="" width="563"><figcaption></figcaption></figure> <figure><img src="/files/jg5XHGZGDor2SkYv4Ry7" alt="" width="371"><figcaption></figcaption></figure></div>

You can use [**IPI Authenticator**](broken://pages/nfUXXj17mcWMDhwbPL4s) as the OTP generation application.

#### **Step 4:**

After successfully enabling two-factor authentication, you will be prompted to save your **recovery codes**. You will receive 10 recovery codes, each consisting of 8 characters. These can be used in case you are unable to generate an OTP code.

{% hint style="warning" %}
**Important:** Save these recovery codes in a secure place.
{% endhint %}

Two-factor authentication is now configured, and you can use it with your OTP application.

***

### **Using IPI Key for OTP Generation**

If you want to use the [**IPI Key** to generate OTPs](/use-cases/ipi-key/password-manager-and-otp-generator.md#enabling-otp-input-for-your-accounts), when creating your admin account, enter the **Secret Key** provided during the OTP setup in the corresponding field.

![](/files/5ErMDoHeA8ym831jETUc)

The **Secret Key** is a 32-character value provided in **Step 3**.

\
[Learn more about creating accounts via IPI Client](/ipi-client-app/account-management/account-creation.md).\
[Learn more about creating accounts on IES](/ipi-enterprise-server/accounts/how-to-work-with-personal-employee-accounts.md).\
[How to enter credentials with the IPI key](/ipi-key-enterprise-edition/how-to-enter-credentials-with-ipi-key.md).

***

### **Disabling 2FA on IES**

#### **Step 1:**<br>

Go to the **Profile** tab and locate the **One-Time Password** section. Click **Disable 2FA**.

![](/files/UN9NjK9OngG9UhGpMw4H)

#### **Step 2:**<br>

Confirm the action to disable two-factor authentication.

{% hint style="info" %}
Two-factor authentication is now disabled, but you can enable it again at any time.
{% endhint %}

***

### **Resetting Recovery Codes**

When you disable and then re-enable 2FA, your recovery codes will be reset.

{% hint style="info" %}
**Note:** If you reset the OTP app without disabling 2FA, the recovery codes will **not** be reset.
{% endhint %}

***

### **Logging In with a Recovery Code**

If you cannot enter the OTP code during login, you can use a recovery code.

#### **Step 1:**<br>

Enter your login and password.

#### **Step 2:**<br>

Click on the **One-Time Password** button.

#### **Step 3:**<br>

Click **Log in with a recovery code**.

<figure><img src="/files/f22sYl4Aowh78f7BYxJk" alt="" width="265"><figcaption></figcaption></figure>

#### **Step 4:**<br>

Enter one of your previously saved recovery codes and click **Login**.

<figure><img src="/files/3z3gRoNdZanERXwaCd5m" alt="" width="262"><figcaption></figcaption></figure>

***

{% hint style="info" %}
This completes the setup and usage guide for two-factor authentication on IPI Enterprise Server.
{% endhint %}
