Tuesday, December 17, 2024

SOLVED - Cannot Log in Oracle cloud with 2FA after Phone Change with Oracle Mobile Authenticator

 I have been logging in to Oracle cloud using multi-factor authentication using 2FA with Oracle Mobile Authenticator and it was going fine until I had to change my phone. Both of my phones are android and I THOUGHT that I will simply migrate the apps and keep  using the accounts in my Oracle mobile authenticator same way, but it seems that after migration I lost all the accounts. 

Multi-Factor Authentication (MFA) is a security process that requires a user to provide two or more authentication factors to access a system, network, or application. Two-Factor Authentication (2FA) is a type of Multi-Factor Authentication that requires a user to provide two authentication factors:

  • Something you know (password, PIN)
  • Something you have (smartphone, token, or a one-time password sent via SMS or authenticator app)

So I was using 2FA with this Oracle Mobile Authenticator. I tried with my older codes , QR codes, the password, PIN and stuff but nothing worked. No matter, what I tried I simply couldn't log in to Oracle Cloud since the page asked me for a code generated by the authenticator.

Eventually following is the only way I could find to resolve this issue:

I talked in Oracle live chat, and they asked me to find an engineer to send me a bypass code.

If you don't know what Oracle Mobile Authenticator app is then as per docs:

Oracle Mobile Authenticator enables you to securely verify your identity by using your mobile device as a authentication factor. The app generates one-time passwords for login. Or it can receive notifications for login, which can be approved with a simple tap. When this authentication is used on top of username-password, it adds an additional layer of security that is essential for today's online applications.

Features:

  • Generate one-time passwords even when the device is offline
  • Push Notification based approval
  • App PIN for app protection
  • Set up via QR code, Config URL, or by entering key manually
  • Multiple account support
  • Generate OTP for other applications that make use of One-Time Password as per RFC 6238
  • Generate one-time passwords even when the device is offline
  • Push Notification based approval
  • App PIN for app protection


I hope this helps.

No comments: