Two Factor Authentication

Recruitment MarketingPublic

Two-factor authentication (2FA) is a security system that requires two distinct forms of identification to access an account, strengthening its security. Recruitment Marketing users now have the option to enable 2FA, allowing them to add a second step to the login flow where they input a code from an authenticator app such as Google Authenticator. Google Authenticator is a mobile app that allows the user to fetch a key via QR code and, based on that key, generate a new code every 30 seconds.

Enabling 2FA

  1. Go to your User Settings, which is accessed via the user menu at the top right of the page.
    User settings menu
  2. Click the pencil icon to Edit your user settings.
  3. Click the Two Factor Authentication link.
    two factor authentication setting
  4. Click the enable button on the Two Factor Authentication panel.
    enable 2 factor authentication.png
  5. Scan the QR code using the Google Authenticator app or similar.
    scan_qr_code.png
  6. Enter a code from the app and click Confirm and Enable Two Factor to enable Two Factor Authentication.
  7. Take a copy of the backup codes.
    backup_codes.png
     

Displaying 2FA Enabled/Disabled

Whether 2FA is enabled can be seen in the User Settings. An organisation admin can see if a user in the company has 2FA enabled in User Management as well.

2FA user management

Logging in with 2FA

  1. Log in with an email and password as normal.
  2. This will load a new page where the code from the authenticator app can be entered.

enter_code.pngIf access to the authenticator app is lost, a backup code can be entered instead. Each of the backup codes can only be used once.

Disabling 2FA

  1. Go to User Settings Edit page
  2. Click the Two Factor Authentication link.
  3. Enter a password and click Disable under Two Factor Authentication.
    disable 2FA.png

An organisation admin can disable 2FA for any of the organisation's users via User Management.

Enforcing 2FA for all Users

It is possible to enforce the 2FA policy for all the users of a company, which can be done from the Organisation Settings page.

organisation settings page

To enable the policy:

  1. Click the Enforce multi-factor auth for users checkbox.
  2. Click Save.

From this point on, all users in the organisation will be required to set up 2FA to continue accessing the app.

To disable the policy:

If the checkbox is unticked and changes are saved, users who haven't set up 2FA will be able to access the app again.

Comments

0 comments

Article is closed for comments.