Skip to content

Two-factor sign-in

With two-factor sign-in, you enter a code from an authenticator app on your phone after your password. A stolen password alone won't open your account.

Who must use it

  • Owners and admins, always.
  • Everyone on the team, when your firm requires it.
  • Firmdesk's own staff.

Anyone else can turn it on for themselves. If you must use it and haven't set it up yet, you set it up at your next sign-in, before anything else opens.

Set it up

  1. Install an authenticator app on your phone if you don't have one. Microsoft Authenticator, Google Authenticator, 1Password and Bitwarden all work.
  2. Open the menu with your name at the bottom of the sidebar and choose User settings. Under Two-factor sign-in, click Set it up.
  3. In the app, add an account and scan the QR code. If you can't, click Can't scan it?, choose to enter a setup key in the app, name the account Firmdesk and type the key shown (it's time-based).
  4. Enter the 6-digit code from the app and click Turn on two-factor.
  5. Save the ten recovery codes that appear, then click I've saved them.

New team members are offered the same setup right after they choose their password.

Save your recovery codes

They're shown only once. Print them or keep them in your password manager, not on the phone itself.

Sign in with a code

After your password, Firmdesk asks you to Enter your code. Open the app, type the 6-digit code for Firmdesk and click Continue. The codes change every 30 seconds.

On a computer that's yours, tick Trust this browser for 30 days: that browser won't ask for a code again for 30 days. Your password is still asked every time.

If you don't have your phone

Enter one of your recovery codes instead of the app's code. Each works once, and signing in with one doesn't trust the browser.

To get a fresh set, go to User settings › Two-factor sign-in, click New recovery codes, enter your password and click Make new codes. The old codes stop working as soon as the new ones are made. The same section shows how many codes you have left.

Move to a new phone

  1. In User settings › Two-factor sign-in, click Set up a new phone.
  2. Enter your password and click Continue.
  3. Set up the new phone as above.

Your old authenticator and recovery codes stop working, and browsers you trusted ask for a code again. You get new recovery codes at the end.

Turn it off

In User settings › Two-factor sign-in, click Turn off, enter your password and click Turn it off. The option isn't there when you must use two-factor: to change phones, use Set up a new phone.

Require it for the whole team

Owners and admins can require it:

  1. Go to Settings › Two-factor sign-in.
  2. Tick Everyone on the team must use two-factor sign-in.
  3. Click Save.

Anyone who hasn't set it up does so at their next sign-in. The Your team table shows where each person stands: On, Off, Invited or At next sign-in.

When someone loses their phone

If a team member lost their phone and has no recovery codes, an owner or admin can go to Settings › Two-factor sign-in and click Lost phone in their row. Their two-factor is removed. If they must use it, they set it up again at their next sign-in. For your own login, use Set up a new phone instead.

Who can reset whom:

  • An owner can reset anyone's, other owners' included.
  • An admin can reset members' and other admins', but not an owner's. An owner's row says An owner resets it.
  • Someone who also belongs to another firm on Firmdesk, on its team (even if inactive there) or signing in to its client portal, can't be reset by any of their firms. Their two-factor goes with their login, so removing it would change how they sign in to the other firm too. Their row says Also at another firm: Firmdesk support resets it: write to us at the address under Help in the sidebar. Every firm they belong to sees the reset in Settings › Activity.

Good to know

  • Two-factor belongs to your login, so it covers every firm you belong to. If you're an owner or admin in any of them, or any of them requires it, you can't turn it off.
  • After a few wrong codes, wait a moment before the next try.
  • If the first code doesn't match during setup, check that your phone's clock is set automatically.
  • Turning it on or off, new recovery codes and resets are recorded in Settings › Activity.
  • Your clients don't use an authenticator app: the portal can email them a code when they sign in. See The client portal, as your clients see it.