# Scanning pages behind a login

**Category:** [Accessibility](https://help.totalctrl.app/hc/totalctrl/totalctrl-help-center/en-US/categories/accessibility-1)
**Updated:** 2026-10-04

## Authenticated scanning

To scan pages that require sign-in, open the project's **Settings** and enable **Authenticated scanning**. Provide:

- the **login page URL**,
- a **username** and **password** for a test account.

Before each scan the scanner visits the login page, fills the credentials, submits the form, and then crawls with that session active. You can optionally supply CSS selectors for the username, password, and submit controls if auto-detection doesn't find them.
## Security

The password is **encrypted at rest** and never shown again after you save it. Use a dedicated low-privilege test account.
## MFA is not supported

Two-factor / MFA logins can't be automated, so the test account you use for scanning must have MFA disabled. Use a service account created specifically for accessibility scanning rather than a real person's login.

---

## Related Articles

- [Scheduling, alerts & automation](https://help.totalctrl.app/en-US/articles/accessibility-automation)
- [Checking PDF documents (PDF/UA)](https://help.totalctrl.app/en-US/articles/accessibility-pdf-ua-1)
- [CLI & browser extension (developer tools)](https://help.totalctrl.app/en-US/articles/accessibility-cli-and-extension-1)
- [Scan limits & fair use](https://help.totalctrl.app/en-US/articles/accessibility-limits)
- [Getting started with Accessibility](https://help.totalctrl.app/en-US/articles/accessibility-getting-started)

---
[← Back to TotalCtrl Help Center](https://help.totalctrl.app/en-US/)