Skip to main content

Virtual MFA

Last updated 10/05/2026

Virtual MFA is a widely used security verification method. When logging in, users must enter not only the usual "username + password" but also a dynamic code provided by virtual MFA. Virtual MFA effectively prevents account risks caused by password leaks and greatly improves account security. Besides login, any sensitive account operation can be protected by virtual MFA.

Typically, users bind the account's MFA key in a mobile app in advance. Each time MFA is needed, they open the app and enter the current dynamic code to complete MFA verification.

This section describes virtual MFA support in AE in detail, including enabling it for individual accounts and enforcing it across the entire cluster.

1. Enable or disable MFA for your account​

1.1 Enable MFA for your account​

Users with high security requirements for their personal accounts can go to the Personal Center page from the menu in the upper-right corner of the web page and set up virtual MFA for their account

In the Account Security section, click Enable for the Virtual MFA item to start binding MFA:

After you click Enable, enter your password to verify your identity:

In the binding step, download an authenticator app or use the WeChat Mini Program, open it, and scan the QR code in the center of the screen to get the binding information. If you can't scan the code, click Can’t scan code? to switch to manual entry.

After you scan the code or enter the key, the authenticator app adds an account (depending on the app, you may need to save the account manually). You can then see the 6-digit verification code for this account. Enter it in the corresponding field on the page and complete the verification to bind MFA.

After binding, you need to log in again, and you'll use the virtual MFA you just bound during that login. For details, see section 3, "Login process after MFA is enabled."

1.2 Disable MFA for your account​

To disable MFA, go to the same Virtual MFA item in the Account Security section and click Disable to start turning off MFA:

After you click Disable, enter the MFA dynamic code to verify your identity. MFA is then turned off, and you can also delete the bound MFA information from the authenticator app:

2. Virtual MFA management​

System admins can go to the System Settings page from the menu in the upper-right corner of the web page and manage the cluster's virtual MFA on the Virtual MFA tab of Security Center, including enforcing MFA for all users or unbinding a user's MFA.

2.1 Turn Compulsory MFA on or off​

If you have high requirements for overall system security, we also provide global management that requires all users to bind MFA. System admins can turn Compulsory MFA on or off.

After Compulsory MFA is turned on, all users who haven't enabled MFA are required to bind virtual MFA when logging in, and they can complete login only after binding it. If a user binds and then unbinds MFA, they must bind MFA again at their next login.

After Compulsory MFA is turned off, users are no longer required to bind virtual MFA, but virtual MFA that is already bound isn't unbound.

2.2 Unbind virtual MFA for a specific user​

If a user can't get the virtual MFA dynamic code, for example because they lost their device or accidentally deleted the authenticator app, a system admin can unbind virtual MFA for that user on the virtual MFA management page.

If a system admin can't get the MFA dynamic code, they can contact ThinkingAI staff to unbind it.

3. Login process after MFA is enabled​

After virtual MFA is enabled, once a user passes password verification, they proceed to MFA verification. Open the authenticator app you bound MFA with earlier and enter the dynamic code it currently shows. After successful verification, you're logged in to AE.

Note that if you use third-party login, MFA verification is skipped.

Was this page helpful?