Two-factor authentication
Two-factor authentication means signing in needs your password and a code from an authenticator app. It’s the single most effective thing you can do to protect an account holding research data.
Turning it on
- Open Account from your user settings.
- Find 2FA Authentication and expand it.
- Scan the QR code with an authenticator app, or enter the secret by hand.
- Type the six-digit code the app shows, and confirm.
Then generate recovery codes — properly
As soon as two-factor is on, the Account page tells you to generate recovery codes, and you should do it immediately. These are one-time codes that get you in when you don’t have your authenticator.
Two things people get wrong:
- Freshly generated codes don’t work until you press Confirm. Save them somewhere safe first, then confirm. Until you do, they’re inert.
- Codes are shown once. Store them somewhere that isn’t the device with the authenticator on it — a password manager, or printed and filed.
Without recovery codes, losing your phone locks you out of your account permanently.
Signing in with it on
After your password you’re asked for a code. If you can’t reach your authenticator, choose to use a backup recovery code instead. Each code works once.
Turning it off
Unlinking the authenticator from the Account page turns it off. Recovery codes stay visible after unlinking because they remain a live second factor until you remove them too.
Studies that require it
A study can require two-factor for its own members. If you’re a member of one, you’ll be asked to enrol before you can reach that study’s data, whatever your personal setting.