Two-factor authentication is managed in the Keycloak account console (Settings → Security). Enable OTP or WebAuthn when the realm has MFA configured. Review and revoke devices anytime. A new sign-in may send a security email if you opted into security notices.