Multi-Factor Authentication (MFA) Setup Guide

Multi-Factor Authentication (MFA) adds an extra layer of security to your account by requiring users to verify their identity using more than one method. In addition to a password, MFA may prompt for a verification code sent via email or generated by an authenticator app (such as Google Authenticator or Microsoft Authenticator). This significantly reduces the risk of unauthorized access.

This can be found under Organisation Settings> General Settings > MFA

Enable MFA for Users

Do you want to enable MFA for your internal users and external promoters?

Selecting Yes will activate Multi-Factor Authentication across your organisation. MFA will apply to all user types and roles, including internal users and external promoters, ensuring a consistent and secure login experience for everyone.

If No is selected, MFA will remain disabled and users will continue to log in using their existing authentication method.

Set MFA as Mandatory

Once MFA has been enabled, you can choose whether its use is compulsory.

Do you want to set MFA as mandatory for your organisation?

  • Yes – MFA will be mandatory for all users. Users will be required to complete MFA verification each time they log in.
  • No – MFA will be optional. Users wil be able to Skip the option.

This setting allows organisations to balance security requirements with user flexibility based on their operational needs.

If the operator sets MFA as Mandatory (Yes), all users will be required to enter their MFA verification code during login. The authentication process will not proceed until a valid MFA code is provided.

Enter username and password, then click Login

When MFA is set as mandatory, an MFA verification screen will appear during the login process. A one-time MFA code is automatically generated and sent to the operator’s registered email address.

As MFA is mandatory, the Skip MFA option will not be available. The operator must enter the MFA code received via email to complete authentication and continue logging in.

If the operator sets MFA as non-mandatory (No), the login process allows greater flexibility. During login, the operator may either enter the MFA verification code or bypass MFA by selecting the Skip MFA option.

Selecting Skip MFA allows the user to continue logging in without completing MFA, while still keeping the option available for added security when required.

Once MFA is enabled for the organisation, all operators and external users will see a Set up MFA option in the drop-down menu under their profile name, located in the top-right corner of the screen. This option allows users to configure their MFA settings and complete the MFA setup process.

Then the user selects Set up MFA, they will be redirected to the MFA Setup page. On this page, the user can scan the displayed barcode using an authenticator app such as Google Authenticator or Microsoft Authenticator.

After scanning the barcode, the user must enter the 6-digit verification code generated by the app and select Activate MFA to complete the setup process.

After successful activation, a toast notification will appear confirming “MFA Activated Successfully.” Users can reset their MFA configuration at any time by selecting the Reset MFA button, which will reinitiate the MFA setup process.

MFA Authentication Methods

After completing the MFA setup process, operators can authenticate at the login screen using one of the following methods:

  • Authenticator App Code – Enter the 6-digit verification code generated by an MFA application, such as Google Authenticator or Microsoft Authenticator.
  • Email Code – Enter the MFA code automatically sent to the operator’s registered email address.

This allows flexibility while maintaining a high level of account security.

RECENT UPDATES

Multi-Factor Authentication (MFA)

  • Added a new MFA configuration page under Security Settings.
  • Administrators can now enable or disable Multi-Factor Authentication for internal and external users.
  • Provides an additional layer of security by requiring users to verify their identity beyond their password.
  • Helps protect user accounts from unauthorized access and credential compromise.