---
title: "Two-factor authentication | Vizito Help Center"
description: "Two-factor authentication | Two-factor authentication (2FA, MFA) for the Vizito backoffice: a code by email at every sign in, how to require it for all …"
url: https://vizito.eu/faq/account/two-factor-authentication/
language: en
---

# Two-factor authentication

Two-factor authentication adds a second step to signing in to the [Vizito backoffice](https://backoffice.vizito.be/): after the password, the user types a code that Vizito has just emailed to them. It is switched on per location, for every user at once.

## How it works

Vizito sends the second factor by email. There is no authenticator app to install, no phone number to register and no recovery code to keep. The code goes to the address the user signs in with, so what protects the account is that mailbox.

1.  The user signs in with their email address and password as usual.
2.  The page “Two-Factor Authentication” opens, with the field “Authentication Token” and the hint “Enter your 6-digit token”.
3.  Vizito emails a six-digit code from [vizito@vizito.be](mailto:vizito@vizito.be), with the subject “Your Vizito 2FA token is:” followed by the code. The code is valid for ten minutes.
4.  The user types the code and clicks “Verify Token”. A wrong code returns them to the login page with “Invalid token. Please try again.”; after five wrong codes the sign in is dropped and they start again with their password, which sends a fresh code. Too many attempts from one address in a short time block the page for fifteen minutes.

“Cancel” on the code page returns to the login page.

Users who sign in with “Continue with Microsoft”, “Continue with Google” or through SAML never see this page: their identity provider handles the second factor, and Vizito does not add one on top.

## Require it for all users

1.  Open the backoffice and select “Account settings” > “General” in the left menu.
2.  Scroll to the bottom of “Location settings”, to the “Advanced settings” row, and click “Edit”.
3.  Switch on “Require multi-factor authentication for all users” and click “Save”.

The “Advanced settings” row only shows for users who hold the privilege “Change the general settings”. Local admins and Global admins have it, and a [custom role](https://vizito.eu/faq/account/custom-roles/) can hold it too.

From the next sign in on, every user of this location goes through the code page, and every user you add afterwards starts with it on. There is no per-user switch: the setting applies to everyone with a password. See [Advanced settings](https://vizito.eu/faq/account/advanced/) for the rest of that window.

## The code does not arrive

-   **Check the spam or quarantine folder** for mail from [vizito@vizito.be](mailto:vizito@vizito.be). Ask your mail administrator to allow that sender; the same rule covers host notifications and invitations. See [Network requirements](https://vizito.eu/faq/get-started/network-requirements/).
-   **Wait a minute and check the address.** The code goes to the “Email / login” address of the user, exactly as it is stored. A user who reads their mail under an alias or a renamed address gets nothing. An administrator sees the stored address under “Administration” > “Manage users”.
-   **The code has expired.** Ten minutes after it was sent, the code is useless. Sign in again with the password to get a new one, and use the newest email.
-   **The mailbox no longer exists**, for instance after a migration. See the next section.

## Reset it for a user who lost access to their mailbox

Because the second factor is the mailbox, a user who can no longer read it cannot sign in. The “Email / login” of an existing user cannot be changed: it is the address they sign in with and the one reset links and codes go to. Give them a new user on an address they can read, then delete the old one.

You need the privilege “Add, edit and delete users and roles” for this. Local admins and Global admins have it, and a [custom role](https://vizito.eu/faq/account/custom-roles/) can hold it too.

1.  Select “Administration” > “Manage users” and click the user who is locked out. Note their “Role” and, if it is filled in, their “Host CN”, then close the window.
2.  Click “Add”. Fill in their name and, under “Email / login”, the address they can read now. Select the same “Role” and “Host CN”, and click “Save”.
3.  Ask them to set a password with the link Vizito emails to the new address, and to sign in. When the location requires two-factor authentication, their codes go to the new address.
4.  Once that works, click the old user, click “Delete” and confirm.

Deleting the old user signs them out and takes away their access to this location only; the visitor log is not affected. If they work in several locations, repeat the steps in each one. See [User management and user roles](https://vizito.eu/faq/account/user-roles/) for the rest of the “Add” window.

You can only add or delete a user whose role you could hand out yourself, so a locked-out Global admin needs another Global admin. When the person who lost the mailbox is the only one who can manage users, contact us through the chat or at [info@vizito.eu](mailto:info@vizito.eu): see [Account recovery and ownership](https://vizito.eu/faq/account/account-recovery/). We do not switch two-factor authentication off in a chat, and that article lists what we ask for to check who you are.

## Switch it off

Switching “Require multi-factor authentication for all users” back off stops new users from getting it, but it does not take it away from users who already have it: they keep receiving a code at every sign in. To remove it from a user, or from everyone at once, tell us through the chat in the backoffice which users and which location, and an administrator of that location has to ask. There is no switch for this in the backoffice.
