- Administration
- Two-Factor Authentication
Two-Factor Authentication
Overview
Two-Factor Authentication (2FA) adds a second step to signing in to Astalty. As well as your password, you enter a 6-digit code from an authenticator app on your phone — so someone who knows your password still can't get into your account without your device.
Astalty's 2FA works like this:
- Authenticator app. Astalty uses time-based codes from an authenticator app such as Google Authenticator or Microsoft Authenticator. There is no SMS option.
- Recovery codes. When you enable 2FA you're shown a set of single-use recovery codes. Store them somewhere safe — they're how you get back in if you lose your device.
- Account-wide enforcement. The Account Owner can require 2FA across the organisation, targeted at the specific user roles they choose. Users in those roles are blocked from the rest of Astalty until they've set it up.
- Self-management can be locked down. Account Owners can stop Users from switching 2FA off on their own accounts.
Where to go next
- Enable 2FA on your own account — turn 2FA on from your own profile, scan the QR code and save your recovery codes.
- Set up 2FA on the mobile app — complete 2FA setup when you're prompted while signing in to the Astalty app.
- Enforce 2FA across your account — require 2FA for selected roles, and reset a User's 2FA when they're locked out.
- Prevent Users disabling their own 2FA — stop Users turning 2FA off once it's set up.