Skip to content

Conversation

@rowantomas
Copy link

Updated MFA documentation to enhance clarity and detail on setup, recovery, and reset processes.

Description

What did you change?

Reasons

Why did you make these changes?

Content Checklist

Please follow our style when contributing to CircleCI docs. Our style guide is here: https://circleci.com/docs/style/style-guide-overview.

Please take a moment to check through the following items when submitting your PR (this is just a guide so will not be relevant for all PRs):

  • Break up walls of text by adding paragraph breaks.
  • Consider if the content could benefit from more structure, such as lists or tables, to make it easier to consume.
  • Keep the title between 20 and 70 characters.
  • Consider whether the content would benefit from more subsections (h2-h6 headings) to make it easier to consume.
  • Check all headings h1-h6 are in sentence case (only first letter is capitalized).
  • Include relevant backlinks to other CircleCI docs/pages.

Updated MFA documentation to enhance clarity and detail on setup, recovery, and reset processes.
@rowantomas rowantomas requested review from a team as code owners November 19, 2025 21:12
[#mfa-reset-process]
== MFA Reset Process

The MFA reset process depends on your situation and whether you retain access to your account.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@rowantomas just wondering what you mean here by "reset process". What's the actual task for this how-to section? Sounds like its something like "Add a new authenticator app"? But then it mentions regenerating a code so I'm not 100% sure the intention of the new section


If you have lost access to both your authenticator app and recovery code, you are locked out of your CircleCI account. CircleCI cannot bypass MFA for security reasons. The only way to regain access is through your recovery code. Support cannot reset MFA if you have no recovery code and cannot verify your identity.

=== Scenario 3: Support-initiated MFA reset
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Does this 3rd scenario mean that if you lose your recovery code you might actually be able to regain access with help from support? As this contradicts the previous section we should maybe tighten up the language a bit?

CircleCI does not manage or enforce MFA for VCS logins – it relies entirely on the provider's authentication system.

[#support-escalation]
== Support Escalation Summary
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This seems like internal docs for the support team rather than customer facing info?

Check that the time on your device is up to date. If your authenticator app does not automatically sync time, check for a setting to re-sync it. If you continue to have issues and can't use the OTP, you can use your recovery code to authenticate instead. You can then remove and re-add the MFA factor.

[#vcs-mfa]
== Enabling MFA for VCS Logins
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I would move this before the troubleshooting section ideally if we really need it, maybe after the intro

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants