Skip to main content

Multi-Factor Authentication (MFA) — Setup Guide

Written by Sonja Gebhardt

Case Management supports 2-step verification to keep client data safe. Verification uses an authenticator app (e.g. Microsoft or Google Authenticator), with email/SMS codes as a fallback.

For organisation Owners: turning MFA on

  1. Go to My Organisation.

  2. Open Security Settings.

  3. Switch on Require Multi-Factor Authentication.

This enforces 2-step verification for all users in your organisation. Turning it on does not set anything up for individual users — each person is simply challenged at their next sign-in.

Note: staff who sign in with Microsoft SSO complete Microsoft's own MFA instead, so they won't see the local MFA prompt.

For staff: setting up your authenticator app (recommended)

  1. Sign in, then open the account menu (top-right) and choose Security.

  2. Click Set up authenticator app.

  3. Scan the QR code with your authenticator app — or type in the secret key shown on screen if you can't scan.

  4. Enter the 6-digit code from your app and click Confirm and activate.

  5. Save your recovery codes. They're shown once only — store them somewhere safe (e.g. a password manager). Each code works one time.

If you skip this step, that's OK — you'll receive verification codes by email (and SMS if a UK mobile number is on your account) instead.

Signing in with MFA

  1. Enter your email and password and click Sign in (choose your organisation if you have more than one).

  2. When prompted with “Enter your 2-step verification code”:

    • Enter the 6-digit code from your authenticator app, or

    • Click Send me a code by email/SMS instead — codes expire after 10 minutes, and you can click Resend if needed.

  3. Click Verify.

How often will I be asked? Roughly every 30 days, or sooner if you sign in from a different network/IP address than last time.

Locked out? Five wrong codes trigger a 15-minute lockout. Wait and try again, or ask an admin to reset your MFA.

If you lose your phone or authenticator app

  • Use one of your saved recovery codes at the verification prompt (each works once).

  • Running low on codes? Go to Security → New codes to generate a fresh set (this invalidates the old ones).

  • You can also remove the app via Security → Remove authenticator app — future challenges will then come by email/SMS.

  • No recovery code and no working email/mobile? Contact your organisation admin.

For Owners: resetting a user's MFA

  1. Go to My Organisation → Users.

  2. Open the actions menu for the user and choose Reset MFA and mobile number.

  3. This clears their authenticator, recovery codes, stored mobile number, and any lockout. At their next sign-in they'll be challenged again and can re-enrol from scratch.

Did this answer your question?