CookiePal Logo
CookiePal Logo
Log in

Features

Utilize advanced features and integrate CookiePal with other tools.

Set up MFA before it becomes required

Learn the Cognito MFA rollout timeline, how to enroll an authenticator app, and how account recovery works before enforcement begins.

Table of contents

back

to the top

CookiePal is rolling out Cognito MFA in phases so teams can enable it with less friction before enforcement begins. This guide explains the rollout timeline, how to set up your authenticator app, which users must enroll, and what to do if you lose access to your device.

Understand the rollout timeline

CookiePal is rolling out Cognito multi-factor authentication (MFA) in phases to avoid a support spike and give teams time to prepare.

1. Week 1: MFA is available as optional. Users can set it up proactively from their account settings.
2. Weeks 2-3: Teams should finish onboarding users, make sure exempt accounts are documented, and confirm recovery paths.
3. Week 4: MFA becomes required for non-exempt users.

Set up your authenticator app

In the CookiePal web app, go to Account and open the MFA section. Choose Generate QR code, then scan it with an authenticator app such as Google Authenticator, Microsoft Authenticator, or 1Password.

After scanning, enter the 6-digit code from your authenticator to finish setup. Once confirmed, MFA is active on your account and new sign-ins will require the authenticator code.

Know who must enable MFA

When the rollout reaches the required phase, every non-exempt user must complete MFA to sign in. Accounts marked as exempt by your team or by CookiePal support can remain outside the requirement where approved.

If you are unsure whether your account is exempt, check with your internal admin before the required date.

Use recovery options if you lose your authenticator

If you cannot access your authenticator during sign-in, choose Can't access your authenticator? and switch to email recovery. CookiePal will send a one-time recovery code to your account email so you can complete sign-in.

If you no longer control that email address or recovery still fails, ask an admin to reset MFA for your account before attempting another sign-in.

Prepare before MFA becomes required

Before the required phase starts, make sure that:

1. Each user has enrolled an authenticator app.
2. Shared or temporary accounts are reviewed and formally exempted if needed.
3. Admins know how to reset MFA for locked-out users.
4. Every user can receive mail at the email address on their CookiePal account.

Any Questions Left?

Feel free to contact us and we will answer all of yours remaining questions!

Contact Us

Elevate Your Compliance with
CookiePal Today

View PlansTry for FREE

Privacy made simple!

Powered by WESTPOINT

© CookiePal 2026. All rights reserved. CookiePal Limited is registered in the UK. Company no. 15835702.

Terms and ConditionsPrivacy PolicyGet in Touch