Trusted Devices & MFA Recovery
Skip repeat two-factor prompts on devices you trust, revoke them when needed, and recover access with backup codes when you lose your 2FA method.
Two-factor authentication is strongest when it’s painless on the devices you use daily and strict everywhere else. Trusted devices and backup codes are the two tools that make that balance work.
Trusted Devices
When you verify a 2FA code at sign-in, you can check Trust this device. Muin then remembers that browser, and future sign-ins there skip the code step.
Only trust devices that are yours and protected — your own laptop with a lock screen, not a shared front-desk computer or a borrowed machine.
Reviewing and Revoking
Go to Settings → Security. When 2FA is enabled, the Trusted Devices row shows how many devices can currently skip verification.
Click Revoke All to clear the list — every device, including the one you’re on, will be asked for a 2FA code at its next sign-in. Revoke whenever:
- A laptop or phone is lost, stolen, or handed in
- You trusted a device you shouldn’t have
- You’re doing a periodic security review (a good quarterly habit for admins)
Backup Codes — Your Recovery Path
Backup codes are one-time 8-character codes minted when you enable 2FA (and any time you regenerate them). They’re your way in when your usual method is unavailable — phone lost, new device, no signal.
Using a Backup Code
On the verification screen during sign-in, click Use backup code and enter any unused code. Each code works once.
Staying Out of Trouble
- Store codes somewhere safe when they’re shown at setup — a password manager note is ideal. They’re displayed exactly once.
- Watch your remaining count — the Two-Factor row in Settings → Security shows how many backup codes you have left.
- Regenerate when low or exposed — click New Codes (confirm with your password). The old set is invalidated immediately.
If You’re Completely Locked Out
No working method and no backup codes? Contact your organization’s administrator — they can verify your identity and help restore access. This is intentionally not self-service: an attacker with your password shouldn’t be able to talk their way past your second factor.