First Time Logging In
Upon password submission, the user will be asked to set up an authenticator app. Keycloak officially supports Google Authenticator and FreeOTP. They’ll need to download & open the app and scan the QR code.
Afterwards, they can enter the one-time code from their authenticator, and if desired provide a device name, which is not used by Keycloak, but rather for the user to manage 2FA devices in their account.