Settingsbeginner

Enable two-factor authentication

Voluntarily enroll in TOTP-based two-factor authentication from Preferences: scan a QR code with an authenticator app, confirm with a 6-digit code, name devices, and remove them later.

3 min read

Enable two-factor authentication

Two-factor authentication (2FA) adds a second step to signing in: after your password, Atender asks for a 6-digit code from an authenticator app on your phone or computer. Enrollment is voluntary and lives under Preferences, in the Security section — it’s a personal setting, just like your name or your sidebar style, and enrolling doesn’t affect any other user on your team.

Atender uses the standard TOTP (time-based one-time code) protocol, so any authenticator app that supports TOTP works — Google Authenticator, Authy, 1Password, and similar apps are all compatible.

Open the screen

Click Settings → Preferences, then find the Two-factor authentication card under the Security eyebrow. It’s in the Personal part of the Settings sidebar, so no tenant-level permission is required — every user manages their own 2FA independently.

Add an authenticator app

  1. In the Two-factor authentication card, start enrollment. Atender generates a new device and shows you a QR code.
  2. Open your authenticator app and scan the QR code. If your app or device can’t scan (for example, you’re setting up on the same screen you’re viewing), use the manual key printed below the QR code instead — enter it into your authenticator app as a manual TOTP account.
  3. Your authenticator app immediately starts generating a 6-digit code. Type that code into the confirmation field on the Preferences screen.
  4. Once the code is accepted, the device is verified and appears in your list of enrolled devices.

If you close the panel or navigate away before entering a valid code, the half-finished enrollment doesn’t stay verified — it’s discarded automatically so it doesn’t sit around counting against your device limit.

Naming and managing devices

You can give a device a friendly name when you enroll it (for example, “Work phone” or “1Password”), which makes it easier to tell devices apart later if you enroll more than one. Verified devices are listed with their name and the date they were added.

You’re not limited to a single device — enroll a phone and a backup device if you like. The ceiling is 10 devices per account. If you’re at the limit, remove one you no longer use before adding another.

Remove a device

Next to each enrolled device, use the remove action to take it out of rotation. You’ll be asked to confirm before the device is removed. Once confirmed, that authenticator can no longer generate valid codes for your account, and the entry disappears from your device list.

Remove a device if you’ve lost the phone it was on, replaced it, or simply enrolled it by mistake.

Security event log

Enrolling or removing a device isn’t silent — it’s recorded as a security event. Adding a device logs a factor enrolled event, and removing one logs a factor removed event. If you or an admin ever needs to review account security history, these events show exactly when a device was added or taken away, which is useful for confirming that a device you thought you removed is actually gone, or spotting an enrollment you don’t recognize.

Troubleshooting

  • Symptom: My 6-digit code isn’t accepted. Fix: Authenticator codes are time-based and expire after a short window. Make sure the clock on the device running your authenticator app is accurate, then wait for the app to generate a fresh code and try again.
  • Symptom: I can’t scan the QR code. Fix: Use the manual key shown underneath it. Enter it into your authenticator app as a manual account instead of scanning.
  • Symptom: I can’t add another device. Fix: You’ve likely hit the 10-device limit. Remove an old or unused device first, then enroll the new one.
  • Symptom: I started enrolling but never finished, and now I’m not sure if a device is active. Fix: Only devices that show up in your Preferences list with a name and an added date are verified and active. Unfinished enrollments don’t stay verified — check the list rather than assuming an interrupted setup went through.

Tags

How To