Turn on two-factor sign-in (2FA)
Two-factor sign-in adds a second step next to your password: a six-digit, constantly changing code from an authenticator app. If your password ever leaks, your account still cannot be entered without your phone — and the administrator account is your organisation’s most powerful access, so this is where the protection matters most.
Before you start
Section titled “Before you start”- Account: the set-up page is currently available to administrator accounts.
- Device: an authenticator app on your phone — Google Authenticator, Microsoft Authenticator, Authy, 1Password: any TOTP app works.
- After signing in, open the “Account” page and follow the link on the “Two-factor authentication (2FA)” card.
- “Scan with your authenticator app” — scan the QR code with your app. If scanning does not work, enter the key shown below the QR code manually (“If you cannot scan it, enter this key manually:”).
- “Enter the 6-digit code shown by the app” — the page “Submits automatically after the last digit.”
- “Save your recovery codes” — store the 10 single-use codes somewhere safe (a password manager). “They are shown for the last time now — if lost, generate a new set.”
- Click “Continue →” — done, the app works as usual.
If it worked
Section titled “If it worked”The set-up page shows: “Two-factor authentication is ON for this account.” — with the time it was enabled and the number of usable recovery codes. From now on, after your password every sign-in shows the “Two-step verification” page asking for the app’s current six-digit code (“Enter the 6-digit code from your authenticator app.”); the “Use a recovery code instead” link lets you redeem a recovery code instead. Turning it on and off leaves an audit trail.
Common problems
Section titled “Common problems”| What you see | Why | What to do |
|---|---|---|
| “Invalid code.” | The app’s code changes every 30 seconds — it expired, was mistyped, or your phone’s clock is off. | Wait for the next code and enter it fresh; check that your phone’s clock is set automatically. |
| “Too many failed attempts. Please try again in a few minutes.” | The guessing protection kicked in. | Wait a few minutes and try with a fresh code. |
| I lost my phone | Only that device produces the TOTP code. | Sign in with a recovery code, then click “Reset MFA” on the set-up page and set it up again with the new phone. |
| I ran out of recovery codes | Each works only once. | While you can still sign in with the app code: click “New recovery codes” on the set-up page — the old ones become invalid immediately. |
Worth knowing
Section titled “Worth knowing”- Turning it off is yours, the obligation is your organisation’s. “Reset MFA” turns two-factor off on your account — but if your organisation requires administrator two-factor, the system immediately takes you to set it up again (the protection cannot be dropped, only moved to a new device).
- Your setting does not affect how colleagues sign in — two-factor is per account; today administrator accounts can enable it.