---
title: "Two-Factor Authentication (2FA)"
canonical: "https://help.scopious.co.nz/space/KB/716963843/Two-Factor%20Authentication%20(2FA)"
format: markdown
---
> Macro (toc)

# Two-Factor Authentication

Two-factor authentication (2FA) is a security feature that helps protect your account by requiring an additional verification step to confirm it’s really you.

Once enabled, you’ll be prompted for a verification code **after entering your email and password** when signing in.

Currently we support two methods of 2FA:

- Email
- Authenticator App, using a Time-based One-Time Password (TOTP)

## Managing 2FA

1. Click on the user icon in the top right corner.
2. Click **My Profile**.

![image-20251219-011425.png](media://24645536-8bf0-41a0-9098-2a1a8f87b53b)

3. In the security panel click on **MANAGE 2FA**.

![image-20251219-011316.png](media://876f0420-ff84-439b-a149-ef916a40542c)

## Email

> ℹ️ You must have access to your email account to sign in when email 2FA is enabled.

Email 2FA sends a code to your email address.

### Setup

To setup email 2FA ensure you have clicked on the **MANAGE 2FA** then follow:

1. Click on **ENABLE EMAIL 2FA**.

![image-20251219-011510.png](media://0c8dd370-50a9-433a-bd38-4fd0dd67c1aa)

2. Enter the code sent to your email address. Once you have entered the last character it will automatically submit and log you in.

![image-20251219-011851.png](media://9a1892f3-398f-4fda-b0c4-666629ebd636)

From now on you will be required to enter a code whenever you sign in.

If you lose access to your email address, please contact Scopious support for assistance with account recovery.

## Authenticator App

> ℹ️ Most authenticator apps (such as Google Authenticator, Microsoft Authenticator, Authy, Duo Mobile, etc) support time-based one-time passwords (TOTP).

This method generates a new 6 character code every 30 seconds. It requires an authenticator app to generate the codes for you to use.

### Setup

To set up authenticator app 2FA, ensure you have clicked on **MANAGE 2FA**, then follow:

1. Click on **ENABLE AUTHENTICATOR 2FA**.

![image-20251219-012508.png](media://55627926-b8d8-471c-bfd1-66ed1ff3c082)

2. In your chosen authenticator app, scan the QR code or manually enter the secret key. Once you have entered the last character it will automatically submit and log you in.

> ⚠️ You should never let anyone else know this secret or scan the QR code.

![image-20251219-020110.png](media://a5545466-2207-46aa-b833-98c6b7b999f9)

From now on you will be required to enter a code whenever you sign in.

If you lose access to both your authenticator app and backup codes, please contact Scopious support for assistance with account recovery.

### Backup Codes

> ℹ️ If you lose access to your authenticator app and do not have backup codes, you may be unable to access your account.

Backup codes can be used to sign in in the case you no longer have access to the authenticator app. It is recommended you generate these codes as soon as you finished enabling TOTP 2FA. Store these codes in a safe place. Once a code has been used it cannot be used again.

#### Generation

The button to generate these codes can be found after clicking **MANAGE 2FA**. 

![image-20251219-021002.png](media://1dc5ea81-3d2b-4fdf-849b-4a5b9ae69230)

#### Using a Backup Code

1. Sign into your Scopious account.
2. When you're asked for an authentication code, click 'Use a backup code instead'.

![image-20251219-021655.png](media://de680c25-932e-4cc3-b70f-33187e139ebb)

3. Type in your backup code, you will be automatically signed in.

## Switching or Disabling 2FA

To disable 2FA navigate to your profile and click **MANAGE 2FA**, here you will find the buttons to disable or switch the 2FA.

> ℹ️ Once you switch 2FA methods, the previous method will be immediately disabled.

![image-20251219-020646.png](media://84644ede-ba4c-4299-b138-1baf4002bb5d)