Skip to main content

Enable two-step authentication for a user

Learn how to set up two-step authentication for users to access their ExpenseIn accounts.

J
Written by Jack

Two-step authentication adds an extra layer of security by requiring two forms of verification when users sign in to their accounts. When enabled, users must enter a unique passcode generated by an authenticator app in addition to their email address and password.

In ExpenseIn, two-step authentication can be enabled for individual users or enforced across the entire account. Follow the relevant section below to enable two-step authentication for your users.

Before you start

Before enabling two-step authentication, please note the following:

  • Users must download a two-step authentication app to their mobile device, such as Google Authenticator, Authy, or Authenticator Plus.

  • Users will need access to their mobile device each time they sign in to generate a passcode. If their device is lost, stolen, or damaged, the user must contact an Account Administrator to reset or disable two-step authentication.

How to enable two-step authentication for an individual user

To enable two-step authentication for a specific user, follow the steps below:

1. Click the Account Name > Admin.

2. By default, you'll be taken to the Users page in the User Management section.

3. Find the user you wish to enable two-step authentication for by using the Filter options available.

4. Click the Edit icon next to the user, or click the three dots icon and select Edit from the drop-down.

5. In the Edit User window, click the Two-Step Authentication tab.

6. Tick the Two-step authentication enabled checkbox.

7. Click Update.

How to enable two-step authentication for all users

To enable two-step authentication for all users, follow the steps below:

1. Click the Account Name > Admin.

2. In the Advanced section, click the Additional Settings subheading.

3. In the Account tab, tick the Require Two-Step Authentication checkbox.

Note: Once enabled, two-step authentication becomes mandatory for all users and cannot be disabled individually in a user's settings.

4. Click Update.

How to configure an authentication device

After two-step authentication has been enabled, users will be prompted to configure it the next time they sign in. They can do this by completing the following steps:

1. Sign in to the ExpenseIn web portal.

2. When prompted, open the authenticator app and add a new account by scanning the QR code.

3. Once configured, return to ExpenseIn and enter the current 6-digit verification code generated by the authenticator app.

4. Click Configure & Sign In to complete the setup.

Once configured, users will be required to complete two-step authentication each time they sign in.

Note:

  • If a user has difficulty scanning the QR code, ask them to move their device further away from the screen. Some devices, particularly Android devices, scan more reliably at a greater distance.

  • If the QR code cannot be scanned, users can select the Can't scan QR code? option to display a manual entry code that can be entered into the authenticator app instead.

  • Users should refer to the documentation for their chosen authenticator app if they require further assistance with setup.

Related Articles

Did this answer your question?