Two-factor authentication (2FA) adds an extra layer of security to your JustLogin account. When enabled, users must verify their identity with a one-time code from an authenticator app in addition to their password. This article explains how administrators enable and manage 2FA company-wide, and how individual users complete setup and log in.
What 2FA Method Does JustLogin Use?
JustLogin supports authenticator-app-based 2FA. During setup, users scan a QR code using a supported app, which then generates a fresh 6-digit code every 30 seconds to use at login.
- Supported apps: Google Authenticator, Microsoft Authenticator, Authy, or any standard TOTP-compatible authenticator app.
- Not supported: SMS or email-based one-time passwords (OTP).
Enable 2FA for Your Company (Admin)
2FA settings are managed through User Admin β Settings β Security.
- Go to User Admin β Settings β Security.
- Check Enable 2FA to turn on two-factor authentication for all users in your company.
- Optionally, check Make 2FA Mandatory to require every user to complete 2FA setup before they can access the platform.
- Click Save.
The table below summarises how each option affects the user experience at login:
| Setting | What the user sees |
|---|---|
| 2FA enabled, not mandatory | User is prompted to set up 2FA on first login but can click Skip to proceed without completing setup. |
| 2FA enabled and mandatory | User must complete 2FA setup before they can access the platform β there is no option to skip. |
| 2FA disabled | No 2FA prompt appears; users log in with username and password only. |
How Users Set Up 2FA (First-Time Setup)
- Log in with your usual username and password.
- When prompted, open the 2FA setup screen.
- Open your authenticator app and scan the QR code displayed on screen.
- Your app will begin generating 6-digit codes that refresh every 30 seconds.
- Enter the current 6-digit code into the verification field and submit.
- Once the code is confirmed, 2FA is active on your account and you are taken to the platform as normal.
Logging In After 2FA Is Set Up
- Enter your username and password as usual.
- When prompted, open your authenticator app and find the 6-digit code for JustLogin.
- Enter the code and submit.
- Login completes and you are taken to the platform.
Tip: Your phone's clock must be reasonably accurate for codes to work. If you consistently receive invalid-code errors, check that your device's date and time are set to sync automatically. |
Reset or Deactivate 2FA for an Individual User (Admin)
If a user loses access to their authenticator app, or you need to reset their 2FA for any reason, you can deactivate their 2FA from the Users Admin page. The user will then be prompted to re-enrol on their next login.
- Go to User Admin.
- Locate the user in the list. When 2FA is enabled for your company, a 2FA Status column is visible in the user grid.
- Click Deactivate 2FA next to the user.
- Confirm the deactivation. The user's 2FA setup is cleared immediately.
On their next login, the user will be guided through the QR-code setup process to link a new authenticator app.
Important Note: If 2FA is set to mandatory at the company level, the Deactivate 2FA button is disabled for individual users. To reset a specific user's 2FA while mandatory mode is on, temporarily uncheck Make 2FA Mandatory in User Admin β Settings β Security, deactivate the user's 2FA, then re-enable mandatory mode and save. |
Disable 2FA for Your Entire Company (Admin)
- Go to User Admin β Settings β Security.
- Uncheck Enable 2FA. This also clears the mandatory setting automatically.
- Click Save. Users will no longer be prompted for a 2FA code when they log in.
Key Things to Know
- No backup codes: JustLogin does not currently provide backup codes or alternative recovery methods. If a user loses access to their authenticator app, an admin must deactivate their 2FA so they can re-enrol.
- Authenticator apps only: SMS and email OTP are not supported.
- Two levels of control: Admins manage 2FA at the company level (enable/mandatory) and can deactivate it for individual users as needed.
- Where to find settings: All 2FA configuration is in the User Admin module under Settings β Security.