Account security
The key icon in the left rail (Account security) opens your own account's sign-in settings. Changes here only affect you: each user turns their own two-step verification on and off.
What is two-step verification?
When it's on, signing in asks for the 6-digit code from the authenticator app on your phone (Google Authenticator, Microsoft Authenticator, 1Password, Authy…) after your password. The code changes every 30 seconds; even if someone gets your password, they can't get in without it. Each user turns it on for their own account, and the setting only affects you.
Turning it on
- Click the key icon in the left rail (Account security) and press Turn on two-step verification.
- Add a new account in your authenticator app: scan the QR code on screen or type the Setup key.
- Enter the 6-digit code the app shows and press Confirm and turn on.
- Save the 8 recovery codes that appear somewhere safe (Copy codes). They won't be shown again.
Signing in
After your password, the sign-in screen asks for the code. Type the code from your app or a recovery code; if you don't enter it within 5 minutes, sign-in starts over. A wrong code counts as a failed sign-in, just like a wrong password, and hits the same limits. Each code works only once.
Recovery codes
If your phone isn't with you, sign in with one of the recovery codes (for example ABCDE-FGH23); each works once, and the screen shows how many are left. New recovery codes (confirmed with the code from your app) replace the old ones. The codes themselves aren't stored, only a keyed hash, so we can't show you a lost code again.
Turning it off
Turn off needs the code from your app or a recovery code, so someone who takes over your session can't turn it off on their own.
I lost my phone
Sign in with a recovery code, turn verification off and set it up again with your new phone. If you have no recovery code either, ask the account owner or an admin: on the Users screen, the key button on your row (Reset two-step verification) removes it; next time you sign in with your password only and set it up again.
- Only an account owner can reset an account owner's verification, and nobody can reset their own from the Users screen.
- Turning it on or off, new recovery codes and resets are written to the Audit Log; wrong codes show up as failed sign-ins.
Security details
- The authenticator secret is stored encrypted.
- An accepted code is never accepted again; even if the same code is used in two requests at once, only one gets through.
- The password step alone never opens a session: you can't get into the panel until the code is verified.
SemAgent