Enabling MFA
Set up multi-factor authentication for enhanced account security in DealView.
Multi-factor authentication (MFA) adds an extra layer of security to your DealView account. Even if your password is compromised, MFA protects your access.
What is MFA?
MFA requires two things to log in:
- Something you know - Your password
- Something you have - Your phone or security key
This combination makes unauthorized access much harder.
Enabling MFA
Step 1: Access Security Settings
- Go to Settings > Security
- Find the Two-Factor Authentication section
- Click Enable MFA
Step 2: Choose Your Method
Select an authentication method:
| Method | Description |
|---|---|
| Authenticator App | Google Authenticator, Authy, etc. |
| SMS | Code sent to your phone (less secure) |
Authenticator apps are more secure than SMS. They work offline and aren't vulnerable to SIM swapping attacks.
Step 3: Set Up Authenticator App
- Install an authenticator app (Google Authenticator, Authy, 1Password)
- Scan the QR code shown in DealView
- Enter the 6-digit code from your app
- Click Verify
Step 4: Save Recovery Codes
After enabling MFA:
- DealView displays recovery codes
- Save these codes securely
- Each code can only be used once
- Use if you lose your authenticator
Store recovery codes separately from your password. They're your backup if you lose access to your authenticator.
Logging In with MFA
Once enabled:
- Enter your email and password
- You're prompted for MFA code
- Open your authenticator app
- Enter the current 6-digit code
- Click Verify
Codes refresh every 30 seconds.
Using Recovery Codes
If you can't access your authenticator:
- Click Use recovery code on MFA prompt
- Enter one of your saved codes
- Access granted
- Each code works only once
Generate new codes after using them.
Managing MFA
Regenerating Recovery Codes
If you've used or lost codes:
- Go to Settings > Security
- Click Regenerate Recovery Codes
- Save the new codes
- Old codes are invalidated
Changing Authenticator
To switch authenticator apps:
- Disable MFA temporarily
- Re-enable with new app
- Scan new QR code
- Verify with new code
Disabling MFA
To remove MFA (not recommended):
- Go to Settings > Security
- Click Disable MFA
- Enter your password to confirm
- MFA is removed
Organizational MFA
For workspace admins:
Requiring MFA
Enforce MFA for all workspace members:
- Go to Settings > Workspace > Security
- Enable Require MFA
- Set grace period for enrollment
- Users must enable MFA to continue accessing
Monitoring Compliance
View MFA status for users:
- See who has MFA enabled
- Identify non-compliant users
- Send enrollment reminders
Troubleshooting
Codes not working?
- Check your device time is correct
- Codes are time-sensitive
- Use the latest code (they change every 30 seconds)
Locked out?
- Use a recovery code
- Contact support if no recovery codes available
- Verification may be required
Lost phone?
- Use recovery codes immediately
- Disable MFA and re-enable with new device
- Generate new recovery codes