Skip to content

Turn on two-factor sign-in (2FA)

Two-factor sign-in adds a second step next to your password: a six-digit, constantly changing code from an authenticator app. If your password ever leaks, your account still cannot be entered without your phone — and the administrator account is your organisation’s most powerful access, so this is where the protection matters most.

  • Account: the set-up page is currently available to administrator accounts.
  • Device: an authenticator app on your phone — Google Authenticator, Microsoft Authenticator, Authy, 1Password: any TOTP app works.
  1. After signing in, open the “Account” page and follow the link on the “Two-factor authentication (2FA)” card.
  2. “Scan with your authenticator app” — scan the QR code with your app. If scanning does not work, enter the key shown below the QR code manually (“If you cannot scan it, enter this key manually:”).
  3. “Enter the 6-digit code shown by the app” — the page “Submits automatically after the last digit.”
  4. “Save your recovery codes” — store the 10 single-use codes somewhere safe (a password manager). “They are shown for the last time now — if lost, generate a new set.”
  5. Click “Continue →” — done, the app works as usual.

The set-up page shows: “Two-factor authentication is ON for this account.” — with the time it was enabled and the number of usable recovery codes. From now on, after your password every sign-in shows the “Two-step verification” page asking for the app’s current six-digit code (“Enter the 6-digit code from your authenticator app.”); the “Use a recovery code instead” link lets you redeem a recovery code instead. Turning it on and off leaves an audit trail.

What you see Why What to do
“Invalid code.” The app’s code changes every 30 seconds — it expired, was mistyped, or your phone’s clock is off. Wait for the next code and enter it fresh; check that your phone’s clock is set automatically.
“Too many failed attempts. Please try again in a few minutes.” The guessing protection kicked in. Wait a few minutes and try with a fresh code.
I lost my phone Only that device produces the TOTP code. Sign in with a recovery code, then click “Reset MFA” on the set-up page and set it up again with the new phone.
I ran out of recovery codes Each works only once. While you can still sign in with the app code: click “New recovery codes” on the set-up page — the old ones become invalid immediately.
  • Turning it off is yours, the obligation is your organisation’s. “Reset MFA” turns two-factor off on your account — but if your organisation requires administrator two-factor, the system immediately takes you to set it up again (the protection cannot be dropped, only moved to a new device).
  • Your setting does not affect how colleagues sign in — two-factor is per account; today administrator accounts can enable it.

Last updated: