Skip to main content

Two-factor authentication

Turn on two-factor authentication for your own sign-in, save your recovery codes, and get back in if you lose your authenticator app.

Two-factor authentication adds a second step to your sign-in: your password, and then a six-digit code from an authenticator app on your phone. You turn it on for yourself from Profile → Security, and nobody else in your workspace can switch it on or off for you.

Turn on two-factor authentication

You'll need something that can read a QR code off your screen: your phone, or a desktop authenticator app. There's no setup key to type instead.

  1. Click your avatar and go to Profile → Security.

  2. Click Enable 2FA.

  3. Scan the QR code with your authenticator app. Authy, 1Password, and LastPass Authenticator all work.

  4. Type the six-digit code your app shows, then click Enable.

  5. Copy your recovery codes and store them somewhere safe.

Recovery codes

You get ten recovery codes at the end of setup. Any one of them gets you in once, in place of a code from your app, and is then used up. A recovery code goes where an app code goes: type it into the Authentication code box at sign-in, because there's no separate link for it.

You can look up your unused codes any time. Go to Profile → Security, click Configure, and they're listed under Recovery codes with a Copy recovery codes button. The list shows only the codes you have left.

To get a fresh set, turn two-factor authentication off and set it up again.

Heads up: setting it up again issues ten new codes and cancels every old one, including the ones you never used.

Turn off two-factor authentication

Go to Profile → Security, click Configure, then Disable two-factor authentication and confirm. From then on you sign in without a code.

Get back in when you've lost your authenticator app

A recovery code still gets you in. If your recovery codes are gone too, we'll reset two-factor authentication for you.

Start a chat, or email [email protected], and tell us which workspace and which user is locked out. We'll check that you're allowed to make this change before we make it, and we'll have it done within 24 hours on business days. If you haven't heard from us by then, reply on the same thread. You can ask for your own reset, and an Owner or Admin can ask for one on behalf of someone on their team.

A reset switches it off for that user, so it has to be set up again on the new device. Sign in with your email address and password, using Forgot your password if you need to, then set it up again and save the new recovery codes.

Troubleshooting

I still get asked for a code after my two-factor authentication was reset

Give it a minute and try again. If it keeps asking, reply in the same conversation and we'll check the reset went through.

My recovery code doesn't work

Each code works once, and the screen shows the same message for a code you've already spent as it does for a wrong one, which means the code that failed may be one you used and forgot about. Try another from your list.

If you have none left and no authenticator app, start a chat and we'll reset two-factor authentication for you.

FAQ

Can an admin reset two-factor authentication for one of our users?

Only by asking us. Nothing in the dashboard switches it off for another person, and the Authentication column on the Users page just shows who has it turned on.

Email [email protected]: an Owner or Admin can request a reset for someone on their team, and the person locked out can request their own. We check that whoever is asking is allowed to make the change first.

Does using Google or Microsoft sign-in skip two-factor authentication?

No. Once it's on, you'll need a code however you sign in, including through your company's single sign-on.

Can we require everyone in our workspace to use two-factor authentication?

Not through a Simplesat setting. Enforcing single sign-on applies your own multi-factor policy to everyone, because your identity provider then handles the second factor.

Did this answer your question?