Two-step authentication adds an extra layer of security by requiring two forms of verification when users sign in to their accounts. When enabled, users must enter a unique passcode generated by an authenticator app in addition to their email address and password.
In ExpenseIn, two-step authentication can be enabled for individual users or enforced across the entire account. Follow the relevant section below to enable two-step authentication for your users.
Before you start
Before enabling two-step authentication, please note the following:
Users must download a two-step authentication app to their mobile device, such as Google Authenticator, Authy, or Authenticator Plus.
Users will need access to their mobile device each time they sign in to generate a passcode. If their device is lost, stolen, or damaged, the user must contact an Account Administrator to reset or disable two-step authentication.
How to enable two-step authentication for an individual user
To enable two-step authentication for a specific user, follow the steps below:
1. Click the Account Name > Admin.
2. By default, you'll be taken to the Users page in the User Management section.
3. Find the user you wish to enable two-step authentication for by using the Filter options available.
4. Click the Edit icon next to the user, or click the three dots icon and select Edit from the drop-down.
5. In the Edit User window, click the Two-Step Authentication tab.
6. Tick the Two-step authentication enabled checkbox.
7. Click Update.
How to enable two-step authentication for all users
To enable two-step authentication for all users, follow the steps below:
1. Click the Account Name > Admin.
2. In the Advanced section, click the Additional Settings subheading.
3. In the Account tab, tick the Require Two-Step Authentication checkbox.
Note: Once enabled, two-step authentication becomes mandatory for all users and cannot be disabled individually in a user's settings.
4. Click Update.
How to configure an authentication device
After two-step authentication has been enabled, users will be prompted to configure it the next time they sign in. They can do this by completing the following steps:
1. Sign in to the ExpenseIn web portal.
2. When prompted, open the authenticator app and add a new account by scanning the QR code.
3. Once configured, return to ExpenseIn and enter the current 6-digit verification code generated by the authenticator app.
4. Click Configure & Sign In to complete the setup.
Once configured, users will be required to complete two-step authentication each time they sign in.
Note:
If a user has difficulty scanning the QR code, ask them to move their device further away from the screen. Some devices, particularly Android devices, scan more reliably at a greater distance.
If the QR code cannot be scanned, users can select the Can't scan QR code? option to display a manual entry code that can be entered into the authenticator app instead.
Users should refer to the documentation for their chosen authenticator app if they require further assistance with setup.






