Two-factor authentication

Two-factor authentication adds a second step to signing in to the Vizito backoffice: after the password, the user types a code that Vizito has just emailed to them. It is switched on per location, for every user at once.

How it works

Vizito sends the second factor by email. There is no authenticator app to install, no phone number to register and no recovery code to keep. The code goes to the address the user signs in with, so what protects the account is that mailbox.

  1. The user signs in with their email address and password as usual.
  2. The page “Two-Factor Authentication” opens, with the field “Authentication Token” and the hint “Enter your 6-digit token”.
  3. Vizito emails a six-digit code from vizito@vizito.be, with the subject “Your Vizito 2FA token is:” followed by the code. The code is valid for ten minutes.
  4. The user types the code and clicks “Verify Token”. A wrong code returns them to the login page with “Invalid token. Please try again.”; after five wrong codes the sign in is dropped and they start again with their password, which sends a fresh code. Too many attempts from one address in a short time block the page for fifteen minutes.

“Cancel” on the code page returns to the login page.

Users who sign in with “Continue with Microsoft”, “Continue with Google” or through SAML never see this page: their identity provider handles the second factor, and Vizito does not add one on top.

Require it for all users

  1. Open the backoffice and select “Account settings” > “General” in the left menu.
  2. Scroll to the bottom of “Location settings”, to the “Advanced settings” row, and click “Edit”.
  3. Switch on “Require multi-factor authentication for all users” and click “Save”.

From the next sign in on, every user of this location goes through the code page, and every user you add afterwards starts with it on. There is no per-user switch: the setting applies to everyone with a password. See Advanced settings for the rest of that window.

The code does not arrive

  • Check the spam or quarantine folder for mail from vizito@vizito.be. Ask your mail administrator to allow that sender; the same rule covers host notifications and invitations. See Network requirements.
  • Wait a minute and check the address. The code goes to the “Email / login” address of the user, exactly as it is stored. A user who reads their mail under an alias or a renamed address gets nothing. An administrator sees the stored address under “Administration” > “Manage users”.
  • The code has expired. Ten minutes after it was sent, the code is useless. Sign in again with the password to get a new one, and use the newest email.
  • The mailbox no longer exists, for instance after a migration. See the next section.

Reset it for a user who lost access to their mailbox

Because the second factor is the mailbox, resetting two-factor authentication means pointing the user at a mailbox they can read.

  1. As a Local admin or Global admin, select “Administration” > “Manage users” and click the user.
  2. Change “Email / login” to the address they can read now, and click “Save”. The reset link and every future code go to that address.
  3. Click “Reset password” if they no longer know their password either. See Login and password problems.

A user cannot change their own login address, so this always goes through an administrator. When the person who lost the mailbox is the only administrator, contact us: see Account recovery and ownership. We do not switch two-factor authentication off in a chat, but we can move the account to an address on your domain once we have checked who you are.

Switch it off

Switching “Require multi-factor authentication for all users” back off stops new users from getting it, but it does not take it away from users who already have it: they keep receiving a code at every sign in. To remove it from a user, or from everyone at once, tell us through the chat in the backoffice which users and which location, and an administrator of that location has to ask. There is no switch for this in the backoffice.