Two-factor authentication (2FA) adds an extra layer of security to your NOC account by requiring a time-based one-time password (TOTP) in addition to your regular password. This guide covers enabling 2FA, setting up an authenticator app, and managing backup codes.
Supported Authenticator Apps
NOC supports any TOTP-compatible authenticator app, including:
- Google Authenticator (iOS, Android)
- Authy (iOS, Android, Desktop)
- 1Password (iOS, Android, Desktop)
- Microsoft Authenticator (iOS, Android)
- Bitwarden (iOS, Android, Desktop)
Step 1 — Enable 2FA
- Log in to the NOC Dashboard.
- Click your account name in the top-right corner and select Account Settings.
- Click the Security tab.
- Under Two-Factor Authentication, click Enable 2FA.
- You will be prompted to enter your current password to confirm your identity.
Step 2 — Scan the QR Code
- A QR code will appear on the screen along with a text-based secret key.
- Open your authenticator app on your phone.
- Tap the + or Add Account button in your authenticator app.
- Scan the QR code displayed in the NOC Dashboard. If you cannot scan the code, tap Enter manually and type in the secret key shown below the QR code.
- Your authenticator app will now generate a new 6-digit code every 30 seconds.
Step 3 — Verify the Code
- Enter the current 6-digit code from your authenticator app into the Verification Code field in the dashboard.
- Click Verify & Enable.
- If the code is correct, 2FA is now active on your account.
Step 4 — Save Your Backup Codes
After enabling 2FA, NOC generates a set of 10 one-time backup codes. These codes let you log in if you lose access to your authenticator app.
- Copy or download the backup codes displayed on screen.
- Store them in a secure location (e.g., a password manager or a printed copy in a safe).
- Each backup code can only be used once.
Important: If you lose both your authenticator device and your backup codes, you will need to contact support@noc.org with identity verification to regain access.
Logging In with 2FA
- Enter your email and password on the login page as usual.
- On the next screen, enter the 6-digit code from your authenticator app.
- Click Verify to complete the login.
- If you do not have your authenticator device, click Use a backup code and enter one of your saved codes.
Regenerating Backup Codes
If you have used most of your backup codes or want to invalidate the old set:
- Go to Account Settings » Security » Two-Factor Authentication.
- Click Regenerate Backup Codes.
- All previous backup codes are immediately invalidated.
- Save the new set of codes securely.
Disabling 2FA
- Go to Account Settings » Security » Two-Factor Authentication.
- Click Disable 2FA.
- Enter your password and a current TOTP code to confirm.
We strongly recommend keeping 2FA enabled at all times to protect your account.