Introduction
Two-factor authentication (2FA) increases the security of your account by adding an extra layer of protection during login. Even if someone knows your password, they cannot log in without the additional verification code.
This article explains how 2FA works, how to use it, and what to do if you experience any issues.
Two-factor authentication is not enabled by default and SMS credits are not included in the license costs by default.
Would you like to activate 2FA? Email support.plek@bcs-hr.com.
How does two-factor authentication work?
With two-factor authentication, you log in with your email address and password, after which you must enter an additional verification code. You can receive this via:
- Authenticator app (recommended): linked to your account via a QR code. This method is more secure and works without mobile coverage.
- SMS: less secure and dependent on coverage; primarily used as a fallback.
Logging in with 2FA works as follows:
Log in with your email address and password.
If your phone number is not yet registered in the system, enter your phone number. If your phone number is already registered, proceed to step 3.
Enter the verification code you received via SMS.
During your first login, after SMS verification you will be offered the option to scan a QR code to set up an authenticator app. See the chapter 'Setting up an authenticator app' for instructions. Optionally, this step can be skipped and completed later via the general settings.
After confirmation you are logged in.
Sessions and validity
After logging in, a session starts automatically. As long as it is active, you do not need to enter a new verification code. When the session expires, you must log in again.
Default settings:
- Verification code: valid for 5 minutes
- Session duration: stay logged in for 8 hours
Difference between the two:
| Code timeout | Session timeout |
|---|---|
| Time that a single verification code is valid | Time that you remain logged in |
| A few minutes | Several hours |
| You can request a new code | You must log in again |
Support can adjust these timeouts if needed.
Setting up an authenticator app
Before you are logged in:
- Download an authenticator app (e.g. Google or Microsoft Authenticator).
Log in with your email address and password.
Enter the verification code you received via SMS.
- Scan the QR code shown in the authenticator app to set it up, or enter the code manually in the authenticator app.
- Enter the code generated by the app.
After confirmation you are logged in.
If you are already logged in
- Go to 'Settings' via the menu in the top right under your profile.
Navigate to the settings below for Two-factor authentication. - Click 'Set up new authenticator'.
-
Scan the QR code shown in the authenticator app to set it up, or enter the code manually in the authenticator app.
- Enter the code generated by the app.
- Done — the app is linked to your account.
Troubleshooting
I am not receiving a code
- Check that your phone number is correct (for SMS).
- Check your coverage or try requesting a new SMS.
- Try the authenticator app if possible.
My code is not working
- Wait for the next code in your authenticator app.
- Make sure your phone automatically synchronizes its time.
2FA is enabled but I am not prompted when logging in
- You likely still have an active session.
- Log out and log back in to trigger 2FA.
New phone or lost authenticator?
Contact support to reset your 2FA.
Access to secured documents
Optionally, we offer 2FA specifically for documents. The security applies to individual documents, not to entire groups.
If you have just successfully completed 2FA and your session is still active, you can open secured documents without needing to verify again.
You will need to verify again when:
- your session has expired,
- you log in again,
- you use a different device,
- or security settings have been changed.