<h2>Using multi-factor authentication (MFA)</h2><br/><div style="overflow-x:auto"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"><head><meta content="text/html; charset=UTF-8" /><meta name="copyright" content="(C) Copyright 2025" /><meta name="DC.rights.owner" content="(C) Copyright 2025" /><meta name="generator" content="DITA-OT" /><meta name="DC.type" content="concept" /><meta name="DC.title" content="Using multi-factor authentication (MFA)" /><meta name="abstract" content="Learn how to use multifactor authentication tools to securely access your instance." /><meta name="description" content="Learn how to use multifactor authentication tools to securely access your instance." /><meta name="DC.creator" content="ServiceNow" /><meta name="DC.date.created" content="2023-08-03" /><meta name="DC.date.modified" content="2023-08-03" /><meta name="DC.format" content="XHTML" /><meta name="DC.identifier" content="mfa-use" /><link rel="stylesheet" type="text/css" href="../../../CSS/commonltr.css" /><title>Using multi-factor authentication (MFA)</title></head><body id="mfa-use"> <h1 class="title topictitle1" id="ariaid-title1">Using multi-factor authentication (MFA)</h1> <div class="body conbody"><p class="shortdesc">Learn how to use multifactor authentication tools to securely access your instance.</p> <div class="section" id="mfa-use__section_pm3_k34_dpb"><h2 class="title sectiontitle">Login with MFA</h2> <div class="p"><span class="ph">ServiceNow</span> requires authenticator applications that support Time-based One-time Passwords (TOTP). <span class="ph">ServiceNow</span> tests MFA with the following authenticators:<ul class="ul" id="mfa-use__ul_dgx_rm3_zhb"><li class="li"><span class="ph">Google</span> Authenticator</li><li class="li"><span class="ph">Microsoft</span> Authenticator</li><li class="li">LastPass Authenticator</li><li class="li">Authy</li><li class="li">FreeOTP</li><li class="li">Duo</li><li class="li"><span class="ph">Okta</span> Verify</li></ul> <div class="note"><span class="notetitle">Note:</span> Other authenticators not listed might also be compatible, but are not tested by <span class="ph">ServiceNow</span>.</div> </div> <div class="note"><span class="notetitle">Note:</span> For information related to browser specific behavior change, see this <a class="xref" href="https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB0998122" target="_blank" rel="noopener noreferrer">KB article</a>.</div> <div class="tablenoborder"><table cellpadding="4" cellspacing="0" summary="" id="mfa-use__table_g22_2j4_dpb" class="table" frame="void" border="0" rules="none"><colgroup><col style="width:50%" /><col style="width:50%" /></colgroup><tbody class="tbody"><tr class="row"><td class="entry nocellnorowborder" style="vertical-align:top;"><p class="p">If your administrator has enabled multi-factor authentication (MFA) on your instance, you are prompted for a second authentication after entering your user name and password. For details on the MFA login process, see <a class="xref" href="../task/t_LogOnWithMultifactorAuth.html" title="After multi-factor authentication is enabled for your User profile, you can log in with the addition of the passcode that the Google Authenticator app gives you.">Log in with multi-factor authentication</a></p> <p class="p">If you haven't configured a second form of authentication, you will see a configuration page after logging in to guide you through the process of setting up an authentication app. For details on this setup, see <a class="xref" href="../task/t_SetUpMultiFactorAuthUponLogin.html" title="If your administrator enabled multi-factor authentication on your profile but you have not yet set up the application, you can set it up upon login.">Setup multi-factor authentication upon initial login</a>.</p> </td><td class="entry nocellnorowborder" style="vertical-align:top;"><p class="p bold">Validation with authenticator app</p> <br /><img class="image" id="mfa-use__image_tmd_syx_2wb" src="../images/auth-app.png" height="328" width="277" alt="Authenticator" /><br /> <p class="p">Enter the code displayed on your authenticator app to login.</p> </td></tr></tbody></table> </div> </div> <div class="section" id="mfa-use__section_pyc_yj4_dpb"><h2 class="title sectiontitle">Register an authentication device</h2> <div class="tablenoborder"><table cellpadding="4" cellspacing="0" summary="" id="mfa-use__table_qm1_zj4_dpb" class="table" frame="void" border="0" rules="none"><colgroup><col style="width:50%" /><col style="width:50%" /></colgroup><tbody class="tbody"><tr class="row"><td class="entry nocellnorowborder" style="vertical-align:top;"><div class="p">After you've configured an authentication app, you can register other methods for authentication.<dl class="dl"> <dt class="dt dlterm">Biometric authenticators</dt> <dd class="dd">You can use biometric authenticators like fingerprint or facial recognition as your second MFA authentication. If your administrator allows this option, you can configure biometric authenticators using the steps in <a class="xref" href="../task/mfa-setup-bio-auth.html" title="Register a biometric authenticator to use as part of your multi-factor authentication login.">Register a biometric authenticator</a>.</dd> <dt class="dt dlterm">Hardware key authenticators</dt> <dd class="dd">Hardware keys are physical security devices you can use for authentication. You can register a hardware device for use with your instance using the steps in <a class="xref" href="../task/mfa-setup-hardware-key-auth.html" title="Register a hardware key to use as part of your multi-factor authentication login.">Register a hardware security key</a>.</dd> </dl> </div> </td><td class="entry nocellnorowborder" style="vertical-align:top;"><br /><img class="image" id="mfa-use__image_uh2_nyp_dpb" src="../images/biometric-2.png" height="181" width="168" alt="Biometrics" /><br /> <br /><img class="image" id="mfa-use__image_wth_ryp_dpb" src="../images/hardware-key.png" height="224" width="142" alt="Hardware key" /><br /></td></tr><tr class="row"><td class="entry nocellnorowborder" style="vertical-align:top;"><p class="p bold">Validation with Biometric or Hardware Key</p> <br /><img class="image" id="mfa-use__image_cqv_x1y_2wb" src="../images/biometirc-mfa.png" height="315" width="291" alt="MFA - Biometric or Hardware" /><br /></td><td class="entry nocellnorowborder" style="vertical-align:top;">Use the Biometric or Security Key to login.</td></tr></tbody></table> </div> </div> <div class="section" id="mfa-use__section_ilx_bwb_2vb"><h2 class="title sectiontitle">Register a phone number for OTP</h2> <div class="tablenoborder"><table cellpadding="4" cellspacing="0" summary="" id="mfa-use__table_bjc_2wb_2vb" class="table" frame="void" border="0" rules="none"><colgroup><col style="width:50%" /><col style="width:50%" /></colgroup><tbody class="tbody"><tr class="row"><td class="entry nocellnorowborder" style="vertical-align:top;"><dl class="dl"> <dt class="dt dlterm">SMS</dt> <dd class="dd">Admin configures <span class="ph">ServiceNow</span> instance to require users who attempt to login the instance using SMS based OTP.<p class="p">When users attempt to login to <span class="ph">ServiceNow</span>, SMS OTP is sent to the mobile number associated with the sys_user record. Users can enter the six-digit verification code that it sent to the mobile device and verify their identity.</p> </dd> </dl> </td><td class="entry nocellnorowborder" style="vertical-align:top;"><br /><img class="image" id="mfa-use__image_icf_bn2_2vb" src="../images/sms.png" height="187" width="126" alt="SMS" /><br /></td></tr><tr class="row"><td class="entry nocellnorowborder" style="vertical-align:top;"><p class="p bold">Validation with SMS</p> <br /><img class="image" id="mfa-use__image_l5l_p1y_2wb" src="../images/mobile-screen-mfa.png" height="307" width="282" alt="MFA-SMS" /><br /></td><td class="entry nocellnorowborder" style="vertical-align:top;">Enter the 6-digit code sent to the mobile number to login. The code sent is valid for the next 5 minutes. You can use resend code to again send the code.</td></tr></tbody></table> </div> </div> <div class="section" id="mfa-use__section_clt_zvb_2vb"><h2 class="title sectiontitle">Register an Email address for OTP</h2> <div class="tablenoborder"><table cellpadding="4" cellspacing="0" summary="" id="mfa-use__table_xwx_dwb_2vb" class="table" frame="void" border="0" rules="none"><colgroup><col style="width:50%" /><col style="width:50%" /></colgroup><tbody class="tbody"><tr class="row"><td class="entry nocellnorowborder" style="vertical-align:top;"><dl class="dl"> <dt class="dt dlterm">Email address</dt> <dd class="dd">Admin configures <span class="ph">ServiceNow</span> instance to require users who attempt to login the instance using Email based OTP.<p class="p">When users attempt to login to <span class="ph">ServiceNow</span>, Email OTP is sent to the email address associated to the user. User's can enter the six-digit verification code that it sent to the mobile device and verify their identity.</p> </dd> </dl> </td><td class="entry nocellnorowborder" style="vertical-align:top;"><br /><img class="image" id="mfa-use__image_yzf_mxb_2vb" src="../images/email.png" height="156" width="162" alt="Email" /><br /></td></tr><tr class="row"><td class="entry nocellnorowborder" style="vertical-align:top;"><p class="p bold">Validation with Email</p> <br /><img class="image" id="mfa-use__image_bp1_j1y_2wb" src="../images/email-screen-mfa.png" height="334" width="286" alt="MFA-Email" /><br /></td><td class="entry nocellnorowborder" style="vertical-align:top;">Enter the 6-digit code sent to the email address to login. The code sent is valid for the next 5 minutes. You can use resend code to again send the code.</td></tr></tbody></table> </div> </div> </div> </body></html></div>