What is two-factor authentication?
In practice, after entering your password, the platform asks for a 6-digit code generated by an app installed on your phone (Google Authenticator, Microsoft Authenticator, or any TOTP-compatible app). This code changes automatically every 30 seconds.
Why turn it on?
Even if your password were discovered, nobody could sign in to your account without also having access to your phone. It is the most effective protection against account hijacking.
Step 1: install an authenticator app
- Google Authenticator (Android / iOS)
- Microsoft Authenticator (Android / iOS)
- Any other TOTP-compatible app (Authy, 1Password, Bitwarden...)
Step 2: first activation when signing in
1. Sign in as usual
Enter your email and password as usual on the sign-in page.
2. Scan the QR Code shown
The platform then shows a QR Code with instructions:
- Open Google Authenticator or Microsoft Authenticator on your phone.
- Tap Add an account (“+” icon), then choose Scan a QR Code.
- Point your phone's camera at the QR Code shown on the screen.
3. Enter the code shown
Type this 6-digit code into the “Verification code” field of the sign-in page, then confirm. Two-factor authentication is then permanently turned on for your account. The screens of the platform are shown in French in the illustrations.
Can't scan the QR Code?
In your authenticator app:
- Tap Add an account, then choose Enter a setup key (or “Enter manually”).
- Give the account a name (for example the platform's name) and paste the key shown.
- If asked, specify that it is a time-based (TOTP) key, with 6 digits and a 30-second period — these are the default settings of most apps.
Signing in every day
- You enter your email and password as usual.
- The platform asks for the 6-digit code currently shown in your authenticator app (no QR Code is shown again: your account is already enrolled).
Good to know
On mobile, the input field accepts automatic pasting of the code (“one-time code” autocomplete) on most recent browsers.
The code is rejected or has expired
| Likely cause | Solution |
|---|---|
| The code expired before being confirmed (it only lasts 30 seconds) | Wait for the next code shown by the app and enter it quickly. |
| The phone's clock is not synchronised | Turn on “Automatic date and time” in your phone's settings: a clock offset systematically invalidates the codes. |
| A typing mistake (missing or swapped digit) | Carefully re-enter the code shown, without spaces. |
| You used the code of another account of the app | Check that you are reading the entry of this platform. |
Lost phone or app
Solution
Contact an administrator of your organisation on the platform. They can reset your account's two-factor authentication from the administration area (user management). Once reset, you will be asked to enrol a new authenticator (new QR Code) at your next sign-in, exactly as during your very first activation.
Security best practice
- Never share your 6-digit code or the setup key with anyone, including someone claiming to be an administrator or technical support: this information is never asked for by phone or email.
- If your authenticator app offers locking with a PIN or biometrics, turn it on to protect access to your codes.
- If in doubt about a sign-in attempt you did not start, change your password and inform an administrator without delay.