> ## Documentation Index
> Fetch the complete documentation index at: https://docs.tenantcore.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Mailbox MFA

> Understand TenantCore-guided Microsoft OATH/TOTP MFA and when to use it.

# Mailbox MFA

TenantCore can guide an operator through Microsoft OATH/TOTP MFA setup for a mailbox and protect the resulting secret through the credential-vault workflow.

TenantCore-managed MFA is **optional**.

A mailbox does not need to use TenantCore's MFA workflow simply to exist or to connect to a sending platform.

## What TenantCore manages

TenantCore does not replace Microsoft's MFA enrollment experience.

Instead, TenantCore guides the operator through Microsoft's Security Info flow and securely handles the OATH/TOTP secret once Microsoft presents it.

The flow is:

```text theme={null}
Set up MFA
    ↓
Microsoft Security Info opens
    ↓
Add an Authenticator app
    ↓
Use a different authenticator application
    ↓
Can't scan the QR code?
    ↓
Copy manual secret into TenantCore
    ↓
Secret is vaulted
    ↓
TenantCore generates current code
    ↓
Complete Microsoft verification
```

## Why the manual secret is used

Microsoft can display both a QR code and a manual setup option.

TenantCore uses the underlying OATH/TOTP secret so it can protect the seed and generate the current six-digit code only when an authorized operator requests it.

## After enrollment

Once the setup is confirmed, the mailbox security state can show:

* MFA status
* MFA method
* enrollment state
* current code when explicitly requested
* credential-vault synchronization state

The TOTP seed itself should not be exposed back to the normal UI after enrollment.

## MFA and sending integrations

MFA setup is not a hard prerequisite for TenantCore sending integrations.

When a mailbox is being connected to a sending tool, the operator may:

* set up TenantCore-managed MFA first
* continue without TenantCore MFA
* use an MFA method already managed outside TenantCore

This matters because some operators already have Microsoft MFA configured independently.

## Current code generation

TenantCore generates the current TOTP code only when requested.

The generated code is short-lived and should not be written to normal logs, Reports, or browser persistence.

## Security boundary

A request to reveal an MFA code is authorized against the authenticated TenantCore account and the mailbox resource.

Knowing a mailbox email address is not enough to retrieve its security material.
