Multi-Factor Authentication (MFA)

Multi-factor authentication adds an extra layer of security to your account. When enabled, you'll need both your password and a time-based code from an authenticator app to sign in.

Why enable MFA

CRA compliance requires robust access controls for sensitive data. MFA significantly reduces the risk of account compromise—even if your password is exposed.

Enterprise security policies often mandate MFA for all users accessing compliance data. Enabling MFA now prepares you for these requirements.

Prerequisites

Before you begin, install an authenticator app on your mobile device:

App Platforms
Google Authenticator iOS, Android
Microsoft Authenticator iOS, Android
Authy iOS, Android, Desktop
1Password iOS, Android, macOS, Windows

Any TOTP-compatible app will work.

Set up MFA

  1. Navigate to SettingsSecurity.
  2. Click Enable MFA.
  3. A QR code appears on screen.

Scan the QR code

Open your authenticator app and scan the QR code displayed.

Tip: If you can't scan the code, click Show manual setup to reveal a text code you can type into your app.

Verify your code

Enter the six-digit code from your authenticator app. The code changes every 30 seconds.

Note: TOTP codes are time-sensitive. If verification fails, ensure your device's clock is accurate and synced automatically.

Save your backup codes

After verification, you receive ten backup codes. Each code can be used once if you lose access to your authenticator app.

Warning: This is the only time you'll see these codes. Copy them now and store them securely—in a password manager or printed in a safe location. If you lose both your authenticator and backup codes, only an administrator can restore access.

Sign in with MFA

  1. Enter your email and password as usual.
  2. On the MFA verification screen, open your authenticator app.
  3. Enter the current six-digit code.

The code is case-insensitive and spaces don't matter.

If you don't have your authenticator app, click Use backup code and enter one of your saved codes.

Manage MFA settings

Navigate to SettingsSecurity to view your MFA status, including when it was activated and how many backup codes remain.

Regenerate backup codes

If you've used several codes or suspect they're compromised:

  1. Go to SettingsSecurity.
  2. Click Regenerate backup codes.
  3. Store the new codes securely.

This invalidates all previous backup codes.

Disable MFA

  1. Go to SettingsSecurity.
  2. Click Disable MFA.
  3. Enter a code from your authenticator app to confirm.

Caution: Only disable MFA if necessary (e.g., switching devices). Re-enable it immediately afterward.

Organisation MFA requirements

Administrators can require MFA for all organisation members. When MFA is required:

  • New users must set up MFA before accessing the application
  • Existing users see a mandatory setup screen on their next login
  • Users cannot disable MFA themselves

Look for the MFA Required badge on the Security settings page.

Troubleshooting

Code not working

Symptom Solution
Code rejected Wait for a new code (they change every 30 seconds)
Codes consistently fail Check device clock is accurate and auto-syncing
Still failing Remove the account from your authenticator and set up MFA again

Lost authenticator app

Use a backup code to sign in. If you have no backup codes, contact your organisation administrator—they can reset your MFA from the Members page.

Lost both authenticator and backup codes

Only an organisation administrator or owner can restore access. They must verify your identity through another channel before resetting your MFA.

Security best practices

Practice Why it matters
Use a separate device If your laptop is compromised, your phone still protects your account
Back up your authenticator Apps like Authy offer encrypted cloud backups for device transfers
Store backup codes securely Use a password manager or physical safe—never an unencrypted file
Never share codes Legitimate support will never ask for MFA codes
Last updated February 27, 2026
Was this page helpful?
Thanks for your feedback!

Help us improve. What was missing or unclear?