Skip to content

Two Factor Authentication

Views
19951
Last updated

Set Up Two-Factor Authentication

Add a second layer of security to your HappyFox Help Desk account by requiring agents to verify their identity with an authenticator app when they sign in. Admins can enforce this for the whole account, or each agent can enable it for themselves.

Available on all plans

Note Two-factor authentication applies only to agents who sign in with an email and password. If your account uses SSO, configure 2FA through your SSO provider instead.


Enforce 2FA for all agents

As an admin, you can require every agent to set up 2FA before they can access HappyFox.

Before you begin You need the Manage Security permission to access this setting.

  1. Go to Manage > Security.
  2. Click the Two Factor Authentication tab.
  3. Turn on Enforce Two Factor Authentication for all Agents.

    Two Factor Authentication toggle in Security settings

    The Two Factor Authentication tab in Manage > Security.

The next time each agent signs in, they will be prompted to configure 2FA before they can continue.

Agent prompted to configure 2FA on next login

Agents are prompted to configure 2FA on their next login after enforcement is turned on.


Set up 2FA for your own account

Any agent can enable 2FA independently from their account settings, without waiting for an admin to enforce it.

  1. Click your avatar or name in the top navigation to open My Settings.
  2. Go to the Security tab.

Security tab in My Settings

The Security tab in My Settings.

  1. Open an authenticator app on your phone (such as Google Authenticator or any TOTP-compatible app).
  2. Scan the QR code shown on screen, or enter the secret key manually if your app supports it.
  3. Click Verify to complete setup.

After verifying, HappyFox displays a set of backup codes. Save these codes somewhere safe. You can use them to sign in if you ever lose access to your authenticator app.
QR code setup screen

Note Each backup code can only be used once. If you use all of them, you can generate a new set from the Security tab in My Settings. You can also reconfigure 2FA from My Settings at any time. Reconfiguring makes all previous QR codes and verification codes invalid.

 

Backup codes shown after 2FA setup is complete. Download or copy them before closing.


Sign in with 2FA enabled

After 2FA is configured, every sign-in works like this:

  1. Enter your email and password as usual.
    2FA verification code prompt during login
  2. When prompted, enter the verification code from your authenticator app. If you cannot access your authenticator app, use one of your backup codes instead.
    Entering the verification code 
     Backup codes displayed after setup

 

Warning Entering an incorrect verification code twice in a row counts as an invalid login attempt and returns you to the sign-in screen. Repeated failures can result in account lockout.


Continue reading

Account Lockout on Multiple Invalid Login Attempts

Tags