Two-factor authentication¶
Add a second step to your sign-in so that your password alone is not enough to reach the Backoffice.
Two-factor authentication uses an authenticator app on your phone. After you enter your password, you also enter a short code that the app generates, which changes every few seconds.
Prerequisites
- You can sign in to the Backoffice with your username and password.
- You have an authenticator app installed on your phone.
Enter a code when you sign in¶
If two-factor authentication is already set up on your account, you are asked for a code every time you sign in.
- Sign in with your username and password as usual.
- When the code screen appears, open your authenticator app and read the current six-digit code for the Backoffice.
- Enter the six digits. The screen continues on its own once all six are in place, or you can click Verify to confirm.
If you enter the wrong code, the field clears so you can try again. After too many failed attempts you are asked to wait before trying once more.
Set up two-factor authentication¶
You are guided through setup the first time in one of two ways: your workspace may require two-factor authentication and prompt you during sign-in, or you can turn it on yourself from your profile at any time.
- Start setup, either when prompted right after you sign in or from the Two-factor authentication card on your profile.
- In your authenticator app, add a new account by scanning the code shown on screen. If you cannot scan, enter the setup key printed below the code by hand.
- Your app now shows a six-digit code for the Backoffice. Enter that code to confirm the app is set up correctly.
- Save your recovery codes when they appear (see below), then finish.
Warning
If your workspace requires two-factor authentication, you cannot reach the rest of the Backoffice until setup is complete. You can sign out from the setup screen if you need to stop.
Save your recovery codes¶
When setup finishes, the Backoffice shows a one-time list of recovery codes. Each code lets you sign in once if you lose access to your authenticator app.
- Click Copy to copy the codes, or write them down, and store them somewhere safe and private.
- Click Done to continue.
Note
The recovery codes are shown only once, at setup. Keep them where you can find them but no one else can.
To sign in with a recovery code when you do not have your app, click Use a recovery code on the code screen, enter one of your saved codes, and confirm.
Turn two-factor authentication on or off¶
You manage two-factor authentication from your own profile.
- Open your profile and find the Two-factor authentication card. A badge shows whether it is currently Enabled or Disabled.
- Click Enable to start setup, or Disable to turn it off.
- If you are turning it off, confirm when asked.
Note
If your workspace requires two-factor authentication, the option to turn it off is not available to you. If you are locked out, an administrator at your firm can reset it for you.