In this article, you'll learn how to enable two-factor authentication (2FA) via email code per studio, complete missing employee access data, and how your employees then log in with the confirmation code.
Contents
- Prerequisites
- Enable two-factor authentication for a studio
- Add missing email addresses or home studios
- Logging in with two-factor authentication
- Request a new code or expired code
- Too many failed attempts: locked access
- Messages at a glance
Fast lane
- Open Resources / Employees / Two-Factor Authentication.
- Make sure all employees have an email address in their access data and a home studio.
- Turn on the Enable Two-Factor Authentication toggle.
Prerequisites
- Permission: "Configure two-factor authentication" (category Employees & Resources / Employee Management). You assign it under Resources / Employees / Roles in the relevant role.
- Each affected employee has a unique email address in their Access data.
- Each affected employee has a home studio assigned.
Important: For two-factor authentication, the email address from the Access data of the user account counts, not the email address from the employee's personal details. The email address must be unique. For existing employees, existing email addresses are populated into the access data automatically.
Enable two-factor authentication for a studio
You enable two-factor authentication per studio. It then applies to all employees whose home studio is that studio. You find the page via the Two-Factor Authentication menu item.
- Open Resources / Employees / Two-Factor Authentication.
- Turn on the Enable Two-Factor Authentication toggle.
- Confirm the activation. After that, all employees of this studio must log in with two-factor authentication.
As long as there are still employees without an email address or home studio, the feature cannot be enabled. The following note appears: "All employees in this studio must have an email address and a home studio to enable two-factor authentication." A warning also reminds you: "Please ensure all employees have a valid email address and home studio assigned to their account. If they don't, they will experience login issues once 2FA is turned on". Add the missing data first (see next section).
Add missing email addresses or home studios
On the Two-Factor Authentication page you see the list Employees without email address or home studio with the columns Name, Email and Home studio. There you add the missing details directly, without having to open the employee's detail page.
- Use Edit email address to store the email address in the access data.
- Use Edit home studio to assign a home studio to the employee.
As soon as no employee is left in the list, the note "No action needed. You don't have any employees without assigned Home Studio or Email address." appears and you can enable two-factor authentication.
Logging in with two-factor authentication
After activation, logging in works like this for your employees:
- Enter the username and password as usual and start the login.
- The Check your email screen appears. The software sends a 5-digit verification code to the email address from the access data ("We sent a 5-digit verification code to your email").
- Enter the code in the Authentication code field and click Verify.
- After a successful check, the employee is logged in. If they have access to several studios, the studio selection follows.
The code is valid for 15 minutes. The remaining time is shown on the page ("Code expires in … minutes").
Two-factor authentication applies to all logins by your employees, regardless of which application they use to log in.
Request a new code or expired code
If the code did not arrive, the employee clicks Resend code under "Didn't receive the code?". The confirmation "A new code was sent to your email" appears.
An expired code is shown with "The code has expired. Please request a new one." In that case, request a new code via Resend code.
If the account has no valid email address, the message "you don't have a valid email address configured on your account, please contact your studio admin" appears. The administrator then adds the email address in the access data.
Too many failed attempts: locked access
If a wrong code is entered, the message "The verification code you entered is invalid. Please try again." appears and the employee can enter the code again.
After 5 wrong entries, access is locked for 15 minutes. During this time, no login is possible, not even with a new code. The lock cannot be lifted early. After the 15 minutes have passed, logging in is possible again.
Messages at a glance
| Situation | Message |
|---|---|
| Invalid code | The verification code you entered is invalid. Please try again. |
| Code expired | The code has expired. Please request a new one. |
| New code requested | A new code was sent to your email |
| No email address on the account | you don't have a valid email address configured on your account, please contact your studio admin |
| 2FA login failed | Login via two-factor authentication failed. Please try again or contact your administrator. |
| Activation not possible (missing data) | All employees in this studio must have an email address and a home studio to enable two-factor authentication. |