Two-factor authentication adds a second step to signing in. After your password, or after signing in with Google, brandflare asks for a six-digit code from an authenticator app on your phone. Someone who has your password but not your phone cannot get in.
It is each person's own choice, unless the workspace requires it. An owner or admin can require it of everyone on the team.
Setting it up
Go to Profile › Security and choose Set up two-factor. It takes about two minutes.
- Scan the code with an authenticator app such as Google Authenticator, Microsoft Authenticator or 1Password. If you can't scan it, type the key shown beside it into the app instead.
- Enter the six-digit code the app shows, to prove it works.
- Save your backup codes. They are shown once, with buttons to copy or download them.
From then on, every sign-in asks for a code from the app.
Backup codes
A backup code signs you in once in place of the app, for the day your phone is lost, broken or left at home. Keep them somewhere other than your phone: a password manager, or printed.
Under Profile › Security, New backup codes makes a new set. The old set stops working, including any codes you had not used.
Changing phone, or turning it off
Both are under Profile › Security.
- Change phone removes two-factor from your old phone and takes you straight into setting it up on the new one. Your old backup codes stop working and you get a new set.
- Turn off removes it. Signing in asks for your password only. This is not offered while your workspace requires two-factor.
Requiring it for a workspace
Owners and admins can require two-factor of everyone, from Settings › Team, under Two-factor authentication. The card shows how many people on the team have it set up, and the Members table shows where each person stands.
You need two-factor on your own sign-in before you can require it, so the rule cannot lock out the person who set it.
When the rule is switched on:
| Who | What happens |
|---|---|
| People who already have two-factor | Nothing changes for them. |
| People already on the team without it | They get an email that day and have 7 days to set it up. A strip at the top of every page counts the days down, and a reminder email arrives with 3 days left. |
| Anyone still without it after 7 days | The workspace is closed to them. Signing in shows one page, which sets two-factor up; once that is done everything is where they left it. |
| Anyone who joins later | They set two-factor up the first time they sign in, before they see the workspace. Their invitation says so. |
Nothing is removed from the workspace at any point, and checks carry on as normal.
Stop requiring switches the rule off. People who have two-factor keep it, and anyone the rule had closed the workspace to can open it again.
If someone loses their phone
A backup code gets them in. If they have lost those as well, an owner or admin can reset their two-factor from Settings › Team: Reset two-factor beside their name. Their authenticator app and backup codes stop working, they are told by email, and they set two-factor up again from their own sign-in. Only reset someone when you are sure it is them asking.
The owner's two-factor cannot be reset from the Team page. An owner who has lost both their phone and their backup codes should get in touch and brandflare resets it after checking who is asking.
Who can do what
| Owner and admin | Editor | Viewer | |
|---|---|---|---|
| Use two-factor on their own sign-in | Yes | Yes | Yes |
| See who on the team has it | Yes | — | — |
| Require it of everyone | Yes | — | — |
| Reset a colleague's two-factor | Yes | — | — |
See teams and roles for everything else a role can do.