Features
Utilize advanced features and integrate CookiePal with other tools.
Set up MFA before it becomes required
Learn the Cognito MFA rollout timeline, how to enroll an authenticator app, and how account recovery works before enforcement begins.
Table of contents
back
to the top
CookiePal is rolling out Cognito MFA in phases so teams can enable it with less friction before enforcement begins. This guide explains the rollout timeline, how to set up your authenticator app, which users must enroll, and what to do if you lose access to your device.
Understand the rollout timeline
CookiePal is rolling out Cognito multi-factor authentication (MFA) in phases to avoid a support spike and give teams time to prepare.
1. Week 1: MFA is available as optional. Users can set it up proactively from their account settings.
2. Weeks 2-3: Teams should finish onboarding users, make sure exempt accounts are documented, and confirm recovery paths.
3. Week 4: MFA becomes required for non-exempt users.
Set up your authenticator app
In the CookiePal web app, go to Account and open the MFA section. Choose Generate QR code, then scan it with an authenticator app such as Google Authenticator, Microsoft Authenticator, or 1Password.
After scanning, enter the 6-digit code from your authenticator to finish setup. Once confirmed, MFA is active on your account and new sign-ins will require the authenticator code.
Know who must enable MFA
When the rollout reaches the required phase, every non-exempt user must complete MFA to sign in. Accounts marked as exempt by your team or by CookiePal support can remain outside the requirement where approved.
If you are unsure whether your account is exempt, check with your internal admin before the required date.
Use recovery options if you lose your authenticator
If you cannot access your authenticator during sign-in, choose Can't access your authenticator? and switch to email recovery. CookiePal will send a one-time recovery code to your account email so you can complete sign-in.
If you no longer control that email address or recovery still fails, ask an admin to reset MFA for your account before attempting another sign-in.
Prepare before MFA becomes required
Before the required phase starts, make sure that:
1. Each user has enrolled an authenticator app.
2. Shared or temporary accounts are reviewed and formally exempted if needed.
3. Admins know how to reset MFA for locked-out users.
4. Every user can receive mail at the email address on their CookiePal account.