Security Settings
This guide covers security features including Two-Factor Authentication (2FA), Passkeys, session management, and password security.
Two-Factor Authentication (2FA)
Two-Factor Authentication adds an extra layer of security by requiring a second form of verification in addition to your password.
What is 2FA?
When 2FA is enabled, logging in requires:
- Something you know - Your password
- Something you have - A code from your authenticator app
Even if someone obtains your password, they cannot access your account without the second factor.
Setting Up 2FA
Step 1: Access Security Settings
- Click on your profile menu
- Select Security or navigate to Profile > Security
- Find the Two-Factor Authentication section
Step 2: Enable 2FA
- Click Enable Two-Factor Authentication
- A QR code will be displayed
Step 3: Configure Your Authenticator App
- Open your authenticator app (Google Authenticator, Microsoft Authenticator, Authy, etc.)
- Tap Add Account or the + button
- Select Scan QR Code
- Point your camera at the QR code displayed
Step 4: Verify Setup
- Enter the 6-digit code from your authenticator app
- Click Verify
- Save your recovery codes in a secure location
Using 2FA to Log In
- Enter your username and password as usual
- When prompted, open your authenticator app
- Enter the current 6-digit code
- Click Verify
Tip: Codes change every 30 seconds. If a code doesn't work, wait for the next one.
Recovery Codes
Recovery codes are backup codes that can be used if you lose access to your authenticator app.
Important:
- Each recovery code can only be used once
- Store them in a secure location (password manager, safe, etc.)
- Do NOT store them on your phone with your authenticator app
- Generate new codes if you suspect they've been compromised
Disabling 2FA
- Go to Profile > Security
- Click Disable Two-Factor Authentication
- Confirm your password
- 2FA will be removed from your account
Warning: Disabling 2FA reduces your account security. Only disable if absolutely necessary.
Passkeys (WebAuthn)
Passkeys provide a more secure and convenient way to log in using biometrics or hardware security keys.
What are Passkeys?
Passkeys use the WebAuthn standard to provide passwordless authentication:
- Biometric authentication - Fingerprint, Face ID, Windows Hello
- Hardware security keys - YubiKey, Titan Security Key
- Platform authenticators - Built into your device
Benefits of Passkeys
| Feature | Password | Passkey |
|---|---|---|
| Phishing resistant | No | Yes |
| Requires memorization | Yes | No |
| Can be reused across sites | Often | No |
| Biometric option | No | Yes |
Setting Up a Passkey
Step 1: Access Security Settings
- Go to Profile > Security
- Find the Passkeys section
Step 2: Add a Passkey
- Click Add Passkey
- Enter a name for this passkey (e.g., "MacBook Pro", "YubiKey")
- Click Continue
Step 3: Authenticate
Your browser will prompt you to verify your identity:
- Biometric: Touch fingerprint sensor or look at camera
- Security Key: Insert and tap your hardware key
- PIN: Enter your device PIN if prompted
Step 4: Confirm
Once verified, the passkey is registered and ready to use.
Using Passkeys to Log In
- Go to the login page
- Enter your username
- Click Sign in with Passkey (if available)
- Authenticate using your registered method
Managing Passkeys
Viewing Your Passkeys
In Profile > Security > Passkeys, you can see:
- Passkey name
- Date created
- Last used date
- Synced status (backed up to cloud)
Removing a Passkey
- Find the passkey in your list
- Click the delete/remove icon
- Confirm the removal
Note: You can register up to 5 passkeys per account.
Passkey Best Practices
- Register multiple passkeys - Have a backup in case one is lost
- Use descriptive names - "Work Laptop", "Personal Phone", "YubiKey Backup"
- Keep one hardware key - Hardware keys work even if your devices are lost
- Enable sync - Platform passkeys can sync across your devices
Session Management
Sessions track where and when you're logged into the system.
Viewing Your Sessions
- Go to Profile > Sessions
- View all active sessions
Session information includes:
| Field | Description |
|---|---|
| Device | Browser and operating system |
| Location | Approximate location based on IP |
| IP Address | Network address |
| Last Active | When the session was last used |
| Current | Indicates your current session |
Reviewing Sessions for Security
Regularly check your sessions for:
- Unknown devices - Devices you don't recognize
- Unusual locations - Logins from unexpected places
- Old sessions - Sessions that should have expired
If You See Suspicious Activity
- Change your password immediately
- Enable 2FA if not already enabled
- Review activity logs for unauthorized actions
- Contact your administrator if concerned
Password Security
Password Requirements
Strong passwords should include:
- Minimum 8 characters (12+ recommended)
- Mix of uppercase and lowercase letters
- Numbers
- Special characters (!@#$%^&*)
Changing Your Password
- Go to Profile > Security
- Find the Password section
- Enter your current password
- Enter your new password
- Confirm the new password
- Click Change Password
Password Best Practices
| Do | Don't |
|---|---|
| Use unique passwords for each account | Reuse passwords across sites |
| Use a password manager | Write passwords on paper |
| Change passwords periodically | Share passwords with others |
| Use passphrases when possible | Use personal information |
Forced Password Reset
In some cases, you may be required to change your password:
- Administrator reset your password
- Password policy requires periodic changes
- Security incident detected
When forced to reset:
- You'll be prompted after logging in
- Enter a new password meeting requirements
- You cannot skip this step
Security Recommendations
For All Users
- Enable 2FA or Passkeys - Add a second factor to your account
- Use strong passwords - Or better yet, use passkeys
- Review sessions regularly - Check for unauthorized access
- Report suspicious activity - Contact admin if something seems wrong
For Administrators
- Encourage 2FA adoption - Make it easy for users to enable
- Monitor failed logins - Watch for brute force attempts
- Review user sessions - Check for compromised accounts
- Implement password policies - Enforce minimum requirements
Security Checklist
Use this checklist to ensure your account is secure:
- Strong, unique password set
- Two-factor authentication enabled
- Recovery codes saved securely
- At least one passkey registered (recommended)
- No unrecognized sessions active
- Recent activity looks normal
Troubleshooting
2FA Code Not Working
- Check the time - Ensure your device time is correct
- Wait for new code - Codes expire every 30 seconds
- Use recovery code - If authenticator is unavailable
- Contact admin - If all else fails
Passkey Not Recognized
- Try again - Authentication can sometimes fail
- Check browser support - Ensure your browser supports WebAuthn
- Try different passkey - Use an alternative registered passkey
- Fall back to password - Use password + 2FA instead
Locked Out of Account
If you cannot access your account:
- Try password reset - If email access is available
- Use recovery codes - For 2FA bypass
- Contact administrator - Request account recovery
- Verify identity - Be prepared to prove who you are
Session Shows Unknown Location
IP-based location can be inaccurate:
- VPN usage - VPNs show different locations
- Mobile data - Carrier IPs may show wrong location
- ISP routing - Sometimes routes through different cities
If truly suspicious, change your password and review activity.