> ## Documentation Index
> Fetch the complete documentation index at: https://docs.tenantcore.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Set Up Mailbox MFA

> Configure TenantCore-guided Microsoft OATH/TOTP MFA for a mailbox.

# Set Up Mailbox MFA

TenantCore can guide you through Microsoft's OATH/TOTP enrollment and securely protect the resulting secret.

MFA setup in TenantCore is optional.

## Start the workflow

1. Open the mailbox.
2. Open its security controls.
3. Choose **Set up MFA**.
4. TenantCore opens Microsoft's Security Info experience and keeps the TenantCore setup flow available.

## In Microsoft Security Info

Follow the Microsoft setup flow for an authenticator application.

When Microsoft displays the QR-code step:

1. choose the option to use a **different authenticator application**
2. continue until Microsoft shows the QR code
3. select **Can't scan the QR code?**

Microsoft will show the manual setup information.

## Copy the secret into TenantCore

Copy the manual OATH/TOTP secret into TenantCore.

Do not copy screenshots or recovery information.

TenantCore stores the secret through its credential-vault workflow.

## Complete verification

TenantCore can generate the current six-digit TOTP code from the vaulted seed.

Enter that code into Microsoft's verification screen.

TenantCore then confirms the enrollment state before marking MFA active.

## After setup

The mailbox security view can show:

* MFA active/inactive state
* enrollment state
* current MFA code when explicitly requested
* credential synchronization state

The original TOTP seed should not be treated as normal reusable UI content.

## MFA is not required for every sending connection

If you are connecting a mailbox to a sending tool and do not want TenantCore-managed MFA, choose the option to continue without it.

You can also use an MFA configuration managed outside TenantCore.
