Security & Two-Factor Authentication
Security Settings is where you protect your BusinessHRM account with Two-Factor Authentication (2FA). Two-Factor Authentication adds a second step to signing in, so that even if someone learns your password they still cannot get into your account without a one-time code. These settings apply to your own account; each user manages their own 2FA.
The page opens on the Two-Factor Authentication tab. Each method shows a status indicator: a green dot means it is active and confirmed, a red dot means it is not yet set up.
(Some accounts may also see a Google Recaptcha tab. That tab is managed by the platform administrator and is not covered here.)
Two-Factor Authentication tab
This tab offers two ways to secure your sign-in: by email code, and by an authenticator app. You can turn on either one, or both at the same time. A short notice at the top reminds you what 2FA does.
If your email system is not fully set up, a warning may appear here. If you have permission to manage notification settings, a Verify button links you to where email can be configured. The email method only works once email sending is working.
Setup Using Email
With this method, BusinessHRM emails a one-time code to your account email address each time you sign in.
| Field | What it does |
|---|---|
| Authentication code | The one-time code that is emailed to you. You enter it in the confirmation window to turn the method on. |
To turn on email 2FA:
- In the Setup Using Email section, click Enable.
- BusinessHRM sends a six-digit code to your account email address. The code is valid for 10 minutes.
- In the window that opens, type the code into the code field.
- Click Validate 2FA. The method becomes active and shows a green Active badge.
To turn it off, click Disable in the Setup Using Email section.
Setup Using Google Authenticator
With this method, you use an authenticator app (such as Google Authenticator) on your phone to generate codes. Codes work even when your phone is offline.
Before you start, install an authenticator app on your phone. If you turn this on and lose access to your codes, you will not be able to sign in, so keep your recovery codes safe.
| Field | What it does |
|---|---|
| Your Password | Your current account password. You confirm it before enabling or disabling this method. |
| Authentication code | The current code from your authenticator app. You enter it to confirm setup. |
To turn on authenticator 2FA:
- In the Setup Using Google Authenticator section, click Enable.
- Confirm your password in the window that opens, then click Confirm Password.
- A QR (barcode) appears. Scan it with your authenticator app.
- Click Validate 2FA, enter the current code from your app, and click Validate 2FA again to confirm.
- Once confirmed, the section shows a green Active badge. Until you confirm, it shows "Validate 2FA Pending".
To turn it off, click Disable and confirm your password.
Recovery codes
Recovery codes let you get back into your account if you lose access to your authenticator app. Once the authenticator method is active, two options appear:
- Download Recovery Code saves your recovery codes as a text file (codes.txt). Store this file somewhere safe.
- Regenerate Recovery Code creates a new set of codes and replaces the old ones. Download the new set afterwards.
Using both methods
You can have both the email method and the authenticator method active at once. When both are on, your account uses both for extra protection. Turning one off leaves the other active; turning off the last active method switches 2FA off entirely and clears your authenticator secret and recovery codes.
Permission
The Two-Factor Authentication tab is available to every logged-in user with no special permission; each user manages 2FA for their own account. The Google Recaptcha tab is restricted to the platform administrator and is not part of normal company-admin settings.
Tips
- Turn on at least one 2FA method to protect your account, especially if you are a company administrator.
- The authenticator app method is more reliable than email because it does not depend on email delivery and works offline.
- Always download your recovery codes after enabling the authenticator method, and keep them somewhere safe but separate from your phone.
- If email 2FA will not enable, check that your email (SMTP) settings are working; the email method depends on them.
- Email codes expire after 10 minutes; if a code stops working, start the enable step again to get a fresh one.
- If you regenerate your recovery codes, your old codes stop working immediately, so download and store the new set right away.