Users can strengthen account access by enrolling an authenticator application, saving backup codes, or adding a passkey when the portal policy allows it.
Set up an authenticator application
- Sign in and open Account settings.
- Open the Two-factor or security settings.
- Choose the authenticator-app option.
- Scan the displayed QR code with a compatible authenticator application.
- Enter the six-digit code generated by the authenticator.
- Confirm enrollment and store the provided backup codes in a secure place.
Use or regenerate backup codes
- Use a backup code when another allowed second factor is unavailable.
- Each backup code should be treated as sensitive account information.
- Regenerating backup codes invalidates the previous set, so replace any stored copy.
Add a passkey
- Open the passkey option in account security settings when it is available.
- Start passkey enrollment.
- Follow the device prompt to use Face ID, Touch ID, a security key, or the device PIN.
- Name or confirm the passkey if prompted.
- Sign out and test the passkey from the portal login method selector.
Troubleshooting
- If the passkey option is missing, confirm that the portal policy allows passkeys and that the browser and device support WebAuthn.
- If authenticator codes fail, confirm the device time is correct and enter the newest code.
- If all enrolled methods are unavailable, contact the portal administrator for the approved recovery process.
Figure: Available second-factor methods and enrollment status for the signed-in administrator.