Skip to content

How do I enable Nextcloud two-factor authentication?

Enable Nextcloud two-factor authentication in your security settings, enroll a TOTP or WebAuthn method, and store recovery codes offline before signing out.

Choose a second factor

Time-based one-time passwords (TOTP) use an authenticator app that generates a changing code. WebAuthn uses a hardware security key or a platform authenticator such as a device passkey. Both add a proof beyond the account password. Your Nextcloud web interface shows which providers are enabled for the instance; use the method you can reliably access when travelling or replacing a phone.

Enroll in the web interface

Open your account security settings and start the two-factor setup. For TOTP, scan the displayed QR code with an authenticator app and enter the current code to confirm enrollment. For WebAuthn, follow the browser prompt and touch or unlock the authenticator. Complete the confirmation step before closing the page. If the interface offers a test or confirmation login, use it while the current session is still available.

Save recovery and backup codes

Generate recovery codes and store them in a password manager or another offline location that you can reach without the protected device. Some deployments call these backup codes; whichever label appears, treat each code like a one-time password and do not place the list in a shared folder. If your authenticator supports encrypted backup, keep a separate recovery route rather than relying on one phone. Test that you can locate the codes without publishing them.

Plan account recovery

Before changing phones, register the replacement method while the old method still works. Remove a lost authenticator or security key from the account settings and generate a fresh code set if you suspect exposure. Administrators can have different recovery controls from ordinary users, so follow the options shown for your account and ask an administrator when a policy blocks enrollment.

Use 2FA safely

  • Never approve an unexpected sign-in prompt or share a TOTP value.
  • Check the address bar before entering a code.
  • Keep the password unique even though 2FA is enabled.
  • Review active sessions and revoke devices you no longer recognize.

Two-factor authentication complements secure sharing and activity review; it does not change file permissions. See the YourCloud products page for service information and use support for account-specific access questions.


Was this article helpful?

mood_bad Dislike 0
mood Like 0
visibility Views: 11