Funktionen Preise Dokumentation Kontakt Anmelden Jetzt starten
Sprache

Two factor authentication

How to enrol, what recovery codes are for, how to require two factor for everybody, and what to do when a phone is lost.

Two factor authentication adds a second question to signing in. After your password you are asked for a short code that changes every few seconds on your own phone, so a stolen password on its own is not enough to reach your workspace. You manage it for yourself from My Profile, and for the whole workspace from Settings, then Security.

Turning it on for yourself

You turn two factor on for yourself. Nobody can enrol on your behalf, because the pairing is between the platform and the application on your phone.

  1. Open My Profile and start the two factor setup.
  2. Scan the QR code that appears, using an authenticator application on your phone.
  3. Type the six digit code the application shows, to prove that the pairing worked.

Your secret is stored encrypted. Two factor does not become active until the pairing is proven and your recovery codes have been shown, so an interrupted setup leaves your account exactly as it was.

Screenshot: the two factor setup page, showing the QR code and the field for the six digit code.

Recovery codes

Recovery codes are your way back in when your phone is not available. They are shown once, and you must see them before two factor becomes active.

Save them somewhere safe and offline. Each code works once. You can generate a fresh set at any time from your profile, and doing so invalidates the old set.

Shown once means once. CommonLynk cannot show you the same codes again. If you did not save them, generate a new set from your profile while you can still sign in.

Signing in with two factor

After your password you are asked for the current code from your authenticator. If you do not have your phone with you, you can type one of your recovery codes instead.

Your session is only created after the second step succeeds, so an interrupted sign in leaves you signed out rather than half signed in.

Requiring it for everybody

A workspace administrator can require two factor for every member from Settings, then Security. Anyone who has not enrolled is then made to do so at their next sign in, before their session begins.

CommonLynk refuses to switch this on unless somebody in the workspace could still reset a locked out colleague. Without that, one lost phone would close the workspace permanently.

A lost or replaced phone

Anyone holding the User Management edit permission can reset two factor for another member from that person's user record. The person is then asked to set it up again at their next sign in.

You can also switch your own two factor off from your profile. If your workspace requires it, you will simply be asked to enrol again the next time you sign in.