Multi-factor authentication (MFA)
Multi-factor authentication (MFA) adds a layer of security by requiring a code from your authenticator device in addition to your password.
How to set up MFA
MFA can be set up by going to the "My Account" page after logging in. You need to enter your current password and click on the Set up MFA for your account button.
This will take you to the MFA set-up page, where you set up your authenticator device by following the steps specified.
Step 1: Add the secret code in your authenticator or password manager device
Use an authenticator or password manager app on your computer or phone (like Google Authenticator, Microsoft Authenticator, Authy, Bitwarden, 1Password, 2FAS, Dashlane, or LastPass) to scan the QR code shown and associate it with your account.
Alternatively, if you cannot scan the QR code, you can copy and paste the code shown.
Please note that different apps may have different names for the secret code, e.g. key, One-time password (OTP), secret/security code.
Step 2: Complete the setup
Enter the 6-digit code generated by your authenticator or password manager app to complete the setup.
Also, please note that different apps may have different names for this 6-digit code, e.g. authenticator/verification code, One-time password (OTP or TOTP), 2FA/MFA code, or security code.
After you enter the code from the authenticator, you will be logged in with MFA.
Logging in with MFA
When you log in again in the future, after the login screen where you enter your password, you will be taken to a screen to enter the MFA code generated by your authenticator device.
Trials requiring MFA
Users with an administrator role can turn on the MFA setting for a trial. When a user logs in and goes to their trial page, they will see which trials require setting up MFA in order to gain access.
Attempting to log directly into a trial requiring MFA will take the user to a screen providing access to set it up.
New authenticator device
If you have set up MFA and you change your authenticator device, you can disable MFA and then you can register a new authenticator device.
To disable MFA, go to "My account", where you will see a Disable MFA button under the MFA header.
When you click that button, a form is shown where you need to enter your password and click "Disable MFA".
Then, you can then go to "My account" and set up MFA again.
NOTE: If you have set up MFA and you lose your authenticator device, please contact an administrator of your trial. They will be able to disable MFA so you can register a new authenticator device.
Reset MFA for a user
Administrators (including organisation administrators) can reset a user's MFA from the user account page. The "User details" section shows a Reset MFA link at the bottom.
Clicking the link shows a dialog box to confirm that they want to reset MFA for the user.
Once confirmed, the user's MFA will be disabled and they will receive an email notification. The user can then set up MFA again by going to My account.