# Scanning pages behind a login

**Category:** [Accessibility](https://help.totalctrl.app/hc/totalctrl/totalctrl-help-center/en-US/categories/accessibility)
**Updated:** 2026-10-04

## Authenticated scanning

To scan pages that require sign-in, open the project's **Settings** and enable **Authenticated scanning**. Provide:

- the **login page URL**,
- a **username** and **password** for a test account.

Before each scan the scanner visits the login page, fills the credentials, submits the form, and then crawls with that session active. You can optionally supply CSS selectors for the username, password, and submit controls if auto-detection doesn't find them.
## Security

The password is **encrypted at rest** and never shown again after you save it. Use a dedicated low-privilege test account.
## MFA is not supported

Two-factor / MFA logins can't be automated, so the test account you use for scanning must have MFA disabled. Use a service account created specifically for accessibility scanning rather than a real person's login.

---

## Related Articles

- [VPAT / ACR reports & Accessibility Statements](https://help.totalctrl.app/en-US/articles/accessibility-reports-1)
- [Getting started with Accessibility](https://help.totalctrl.app/en-US/articles/accessibility-getting-started-1)
- [CLI & browser extension (developer tools)](https://help.totalctrl.app/en-US/articles/accessibility-cli-and-extension)
- [Checking PDF documents (PDF/UA)](https://help.totalctrl.app/en-US/articles/accessibility-pdf-ua)
- [Scheduling, alerts & automation](https://help.totalctrl.app/en-US/articles/accessibility-automation-1)

---
[← Back to TotalCtrl Help Center](https://help.totalctrl.app/en-US/)