Security Settings

This guide covers security features including Two-Factor Authentication (2FA), Passkeys, session management, and password security.

Two-Factor Authentication (2FA)

Two-Factor Authentication adds an extra layer of security by requiring a second form of verification in addition to your password.

What is 2FA?

When 2FA is enabled, logging in requires:

  1. Something you know - Your password
  2. Something you have - A code from your authenticator app

Even if someone obtains your password, they cannot access your account without the second factor.

Setting Up 2FA

Step 1: Access Security Settings

  1. Click on your profile menu
  2. Select Security or navigate to Profile > Security
  3. Find the Two-Factor Authentication section

Step 2: Enable 2FA

  1. Click Enable Two-Factor Authentication
  2. A QR code will be displayed

Step 3: Configure Your Authenticator App

  1. Open your authenticator app (Google Authenticator, Microsoft Authenticator, Authy, etc.)
  2. Tap Add Account or the + button
  3. Select Scan QR Code
  4. Point your camera at the QR code displayed

Step 4: Verify Setup

  1. Enter the 6-digit code from your authenticator app
  2. Click Verify
  3. Save your recovery codes in a secure location

Using 2FA to Log In

  1. Enter your username and password as usual
  2. When prompted, open your authenticator app
  3. Enter the current 6-digit code
  4. Click Verify

Tip: Codes change every 30 seconds. If a code doesn't work, wait for the next one.

Recovery Codes

Recovery codes are backup codes that can be used if you lose access to your authenticator app.

Important:

  • Each recovery code can only be used once
  • Store them in a secure location (password manager, safe, etc.)
  • Do NOT store them on your phone with your authenticator app
  • Generate new codes if you suspect they've been compromised

Disabling 2FA

  1. Go to Profile > Security
  2. Click Disable Two-Factor Authentication
  3. Confirm your password
  4. 2FA will be removed from your account

Warning: Disabling 2FA reduces your account security. Only disable if absolutely necessary.

Passkeys (WebAuthn)

Passkeys provide a more secure and convenient way to log in using biometrics or hardware security keys.

What are Passkeys?

Passkeys use the WebAuthn standard to provide passwordless authentication:

  • Biometric authentication - Fingerprint, Face ID, Windows Hello
  • Hardware security keys - YubiKey, Titan Security Key
  • Platform authenticators - Built into your device

Benefits of Passkeys

FeaturePasswordPasskey
Phishing resistantNoYes
Requires memorizationYesNo
Can be reused across sitesOftenNo
Biometric optionNoYes

Setting Up a Passkey

Step 1: Access Security Settings

  1. Go to Profile > Security
  2. Find the Passkeys section

Step 2: Add a Passkey

  1. Click Add Passkey
  2. Enter a name for this passkey (e.g., "MacBook Pro", "YubiKey")
  3. Click Continue

Step 3: Authenticate

Your browser will prompt you to verify your identity:

  • Biometric: Touch fingerprint sensor or look at camera
  • Security Key: Insert and tap your hardware key
  • PIN: Enter your device PIN if prompted

Step 4: Confirm

Once verified, the passkey is registered and ready to use.

Using Passkeys to Log In

  1. Go to the login page
  2. Enter your username
  3. Click Sign in with Passkey (if available)
  4. Authenticate using your registered method

Managing Passkeys

Viewing Your Passkeys

In Profile > Security > Passkeys, you can see:

  • Passkey name
  • Date created
  • Last used date
  • Synced status (backed up to cloud)

Removing a Passkey

  1. Find the passkey in your list
  2. Click the delete/remove icon
  3. Confirm the removal

Note: You can register up to 5 passkeys per account.

Passkey Best Practices

  1. Register multiple passkeys - Have a backup in case one is lost
  2. Use descriptive names - "Work Laptop", "Personal Phone", "YubiKey Backup"
  3. Keep one hardware key - Hardware keys work even if your devices are lost
  4. Enable sync - Platform passkeys can sync across your devices

Session Management

Sessions track where and when you're logged into the system.

Viewing Your Sessions

  1. Go to Profile > Sessions
  2. View all active sessions

Session information includes:

FieldDescription
DeviceBrowser and operating system
LocationApproximate location based on IP
IP AddressNetwork address
Last ActiveWhen the session was last used
CurrentIndicates your current session

Reviewing Sessions for Security

Regularly check your sessions for:

  • Unknown devices - Devices you don't recognize
  • Unusual locations - Logins from unexpected places
  • Old sessions - Sessions that should have expired

If You See Suspicious Activity

  1. Change your password immediately
  2. Enable 2FA if not already enabled
  3. Review activity logs for unauthorized actions
  4. Contact your administrator if concerned

Password Security

Password Requirements

Strong passwords should include:

  • Minimum 8 characters (12+ recommended)
  • Mix of uppercase and lowercase letters
  • Numbers
  • Special characters (!@#$%^&*)

Changing Your Password

  1. Go to Profile > Security
  2. Find the Password section
  3. Enter your current password
  4. Enter your new password
  5. Confirm the new password
  6. Click Change Password

Password Best Practices

DoDon't
Use unique passwords for each accountReuse passwords across sites
Use a password managerWrite passwords on paper
Change passwords periodicallyShare passwords with others
Use passphrases when possibleUse personal information

Forced Password Reset

In some cases, you may be required to change your password:

  • Administrator reset your password
  • Password policy requires periodic changes
  • Security incident detected

When forced to reset:

  1. You'll be prompted after logging in
  2. Enter a new password meeting requirements
  3. You cannot skip this step

Security Recommendations

For All Users

  1. Enable 2FA or Passkeys - Add a second factor to your account
  2. Use strong passwords - Or better yet, use passkeys
  3. Review sessions regularly - Check for unauthorized access
  4. Report suspicious activity - Contact admin if something seems wrong

For Administrators

  1. Encourage 2FA adoption - Make it easy for users to enable
  2. Monitor failed logins - Watch for brute force attempts
  3. Review user sessions - Check for compromised accounts
  4. Implement password policies - Enforce minimum requirements

Security Checklist

Use this checklist to ensure your account is secure:

  • Strong, unique password set
  • Two-factor authentication enabled
  • Recovery codes saved securely
  • At least one passkey registered (recommended)
  • No unrecognized sessions active
  • Recent activity looks normal

Troubleshooting

2FA Code Not Working

  1. Check the time - Ensure your device time is correct
  2. Wait for new code - Codes expire every 30 seconds
  3. Use recovery code - If authenticator is unavailable
  4. Contact admin - If all else fails

Passkey Not Recognized

  1. Try again - Authentication can sometimes fail
  2. Check browser support - Ensure your browser supports WebAuthn
  3. Try different passkey - Use an alternative registered passkey
  4. Fall back to password - Use password + 2FA instead

Locked Out of Account

If you cannot access your account:

  1. Try password reset - If email access is available
  2. Use recovery codes - For 2FA bypass
  3. Contact administrator - Request account recovery
  4. Verify identity - Be prepared to prove who you are

Session Shows Unknown Location

IP-based location can be inaccurate:

  • VPN usage - VPNs show different locations
  • Mobile data - Carrier IPs may show wrong location
  • ISP routing - Sometimes routes through different cities

If truly suspicious, change your password and review activity.

Was this page helpful?