2FA
On this page
Two-factor authentication (2FA) adds an additional layer of security to your DEUNA Admin account by requiring a second form of verification beyond your password.
2FA significantly reduces the risk of unauthorized access by requiring users to verify their identity using two different factors:
- A known factor like a password or an id
- An owned factor like an authenticator app, a phone, or an email
This protects against password theft, phishing attacks, and credential stuffing.
How it works#
DEUNA supports multiple 2FA methods to balance security and usability:
- Authenticator App Time-based one-time passwords (TOTP) generated by apps like Google Authenticator or Authy.
Requirements
2FA can be configured as optional or mandatory based on your organization's security policy:
- Optional: Users can choose to enable 2FA for additional security.
- Mandatory: All users must configure at least one 2FA method to access the platform.
Set up 2FA as a user#
Configure two-factor authentication to secure your account.
1. Access security settings
- Log in to the DEUNA Admin dashboard.
- Click your profile image and select Security.
- Navigate to the Two-Factor Authentication (2FA) section.
2. Choose your 2FA method
Select and configure at least one authentication method. You can enable multiple methods for flexibility.
Option A: Authenticator app
The authenticator app method provides the strongest security and works offline.
- In the 2FA section, click Set up under Authenticator App.
- Install an authenticator app on your mobile device if you haven't already:
- Google Authenticator
- Authy
- Microsoft Authenticator
- Any TOTP-compatible app
- Scan the QR code displayed on screen with your authenticator app.
- Alternatively, manually enter the secret key shown below the QR code.
- Enter the 6-digit verification code from your authenticator app.
- Click Confirm and enable.
Log in with 2FA#
Once 2FA is configured, you'll need to complete an additional verification step when logging in.
Login process
- Enter your email address and password on the login page.
- Click Sign in.
- You'll be redirected to the 2FA verification screen.
Complete 2FA verification
If you have one method configured:
- Enter the verification code from your configured method:
- Authenticator App: Enter the 6-digit code from your app.
- Click Verify.
Manage 2FA#
Update or modify your 2FA configuration at any time.
View active methods
- Go to Profile > Security > Two-Factor Authentication.
- See all your enabled 2FA methods and their status.
- View when each method was last used.
Add additional methods
You can configure multiple 2FA methods for added flexibility:
- Navigate to the 2FA section in your Security settings.
- Click Set up on any method you haven't configured.
- Follow the setup process for that method.
Disable a method
- Go to Profile > Security > Two-Factor Authentication
- Find the method you want to disable.
- Click Disable next to that method.
- Confirm your choice.
Configure 2FA policy as administrators#
Administrators with the "Manage security policy" permission can configure 2FA requirements for their organization.
Enable required 2FA
- Log in as an administrator
- Navigate to Settings > Security & Access.
- Locate the Two-Factor Authentication Policy section.
- Toggle Require 2FA for all users to On.
- Select which methods are allowed for your organization:.
- Authenticator App
- Click Save changes.
View user 2FA status
Monitor 2FA adoption across your organization:
- Navigate to Settings > Users.
- The user list displays a 2FA status indicator for each user:
- Enabled: User has at least one 2FA method configured.\
- Disabled: User has not configured 2FA
- View which specific methods each user has enabled.
Reset user 2FA
If a user loses access to their 2FA methods, administrators can reset their configuration.
- Navigate to Settings > Users.
- Find the user who needs 2FA reset.
- Click the action menu (⋮) next to their name.
- Select Reset 2FA.
- Confirm the reset action.
After reset:
- All of the user's 2FA methods will be disabled.
- Their recovery codes will be invalidated
- If 2FA is required, they must reconfigure it on next login.
- If 2FA is optional, they can log in without it until they reconfigure.