Account settings
Set up two-step verification
Add a second step to password sign-in, so a stolen password is not enough to reach your organisation's data.
Last updated: September 2026
In this article
What you'll need
| Tier | Any plan |
| Platform | Web app, plus an authenticator app on your phone |
| Permission | None — this is your own account. Policy is set by owners and administrators. |
| Where | The sign-in page, then My account → Credentials |
Who needs it
| Who | MFA on password sign-in |
|---|---|
| Owners, administrators, and custom roles with the Admin designation | Required |
| Everyone, if your organisation turns on Require MFA for all password users | Required |
| Everyone else | Not used |
| Anyone signing in with SSO | Not used — your identity provider handles it |
You cannot turn MFA on or off yourself. It follows organisation policy, set under Administration → Organisation Settings → Security.
Enter your code at sign-in
- Sign in with your email and password.
- On Two-step verification, enter the current 6-digit code from your authenticator app.
- Select Verify.
You can paste a recovery code in the same field if you cannot open the app.
If verification fails, start the sign-in again. The verification session expires after a short time, and repeated wrong codes are limited.
Set it up the first time
When MFA is required for you and you have not enabled it yet, you go to setup straight after a correct password:
- Open an authenticator app and scan the QR code on Set up authenticator MFA. If you cannot scan, use the setup key shown on the page.
- Enter the 6-digit Authentication code from the app.
- Select Confirm and continue.
- On Save your recovery codes, copy or print every code and store them somewhere only you can reach.
- Select I saved my codes — continue.
You then reach Home, or the password-change screen if your organisation requires a new password.
Keep your recovery codes
You get 10 recovery codes when you enable MFA. Each works once, and you can use one instead of the app code. My account → Credentials shows how many you have left.
To generate a new set while signed in:
- Go to My account → Credentials → Two-step verification (MFA).
- Under Regenerate recovery codes, enter your current password and an authenticator code.
- Select Generate new codes and save the new list immediately.
Generating new codes invalidates every unused code from the previous set.
Lost your authenticator
- Sign in with your email and password, then enter an unused recovery code.
- Go to My account → Credentials and regenerate your codes so you have a fresh set.
If you have neither the app nor a remaining code, ask an owner or administrator to use Reset MFA on your user — see Manage your users — Reset MFA. Then sign in with your password and set up an authenticator again.
Limitations
- You cannot enable or disable MFA yourself. It follows organisation policy.
- You cannot skip setup once MFA is required for your account.
- MFA does not apply to SSO sign-in. Configure a second factor at your identity provider instead.
- An administrator cannot reset their own MFA. Someone else with owner or administrator access has to do it.
Frequently asked questions
My code is rejected even though I just read it.
Check that your phone's date and time are set automatically. Codes are time-based, so a drifting clock produces codes the server reads as wrong.
I signed in with SSO and was never asked for a code.
That is expected. LambdaAssetCheck MFA applies to password sign-in only.
Can I use SMS or email instead of an app?
No. An authenticator app is the only second factor, with recovery codes as the backup.
I used my last recovery code.
Regenerate a new set immediately from My account → Credentials. If you are locked out first, an owner or administrator resets MFA for you.
Related articles
Previous article: Log in to LambdaAssetCheck
Next article: Install the app on your device →
Was this page helpful?
