Use Two-Factor Authentication
Two-factor authentication (2FA) adds a second step to signing in: after your password, you enter a 6-digit code from an authenticator app on your phone. Any authenticator app that supports TOTP works, for example Google Authenticator. The app shows a new code every 30 seconds.
Before You Start
- Install an authenticator app that supports TOTP on your phone.
- Any role can turn on 2FA for their own account. Admins can also require it for everyone in the organization: see Require two-factor authentication.
Where to Find It
Sidebar: SETTINGS › USER SETTINGS › Security · https://platform.deepinfo.com/app/settings/user-security
The settings are in the Two Factor Authentication card, below Change Password.
Next to the card title, the status reads Enabled (green dot) or Disabled (red dot).
Turn On Two-Factor Authentication
- Go to SETTINGS › USER SETTINGS › Security.
- In the Two Factor Authentication card, select ENABLE TWO FACTOR AUTHENTICATION.
- Scan the QR code with your authenticator app. If you cannot scan it, select COPY SECRET KEY and add the key to the app by hand.
- Enter the 6-digit code that the app shows. The code is sent as soon as all six digits are in. You can also select VERIFY.
- The recovery codes appear. Select DOWNLOAD CODE AND CLOSE. This saves the codes to a text file named
recovery-code-<your e-mail address>.txt, one code per line, and closes the window. - Keep the file somewhere safe, away from your phone.
The status now reads Enabled.
Important
Save your recovery codes when they appear. The platform has no screen to show them again or to create new ones later. Each code works only once.
Sign In With a Code
- Sign in with your e-mail address and password.
- On Two-Factor Authentication Verification, enter the 6-digit code from your authenticator app. You can type or paste it. It is sent as soon as all six digits are in, or select VERIFY.
You then continue to the page you were opening, which is the Global Dashboard unless you followed a link to another page.
Sign In With a Recovery Code
Use a recovery code when you do not have your phone.
- Sign in with your e-mail address and password.
- On Two-Factor Authentication Verification, select Use a Recovery Code. The input changes to eight boxes.
- Enter one of your recovery codes.
That code is now used up. To go back to the app code, select Use Token. If you have neither your phone nor a recovery code, contact support@deepinfo.com.
Turn Off Two-Factor Authentication
- Go to SETTINGS › USER SETTINGS › Security.
- In the Two Factor Authentication card, select DISABLE TWO FACTOR AUTHENTICATION.
- Confirm with DISABLE.
If your organization requires 2FA, you cannot turn it off. The platform shows "Two Factor Authentication is required in your organization." and 2FA stays on.
When Your Organization Requires 2FA
When an admin requires 2FA and you have not set it up, the platform stops you after you sign in, or on your next page load, with a Two-Factor Authentication page. It explains that your organization requires 2FA.
- Select ENABLE TWO FACTOR AUTHENTICATION. The Verify Your Identity window opens.
- Scan the QR code with your authenticator app, or select COPY SECRET KEY and add the key by hand.
- Enter the 6-digit code from the app and select VERIFY.
- Save your recovery codes with DOWNLOAD CODE AND CLOSE.
You then continue to the page you were opening, or to the Global Dashboard. Until you finish, the only other option on the page is Sign Out.
Good to Know
- A new QR code every time. Each time you turn 2FA on, the platform creates a new secret, so you scan a new QR code. You can then remove the old Deepinfo entry from your authenticator app.
- Shared screens. The QR code, the secret key and the recovery codes let someone else pass your second step. Do not show them on a shared screen or in a screenshot.