Skip to main content

Security - Multi-Factor Authentication (MFA)

Updated over 2 weeks ago

Multi-factor authentication (MFA) enhances security by requiring users to verify their identity with two or more credentials when logging in. When MFA is enabled, an authentication code will be required at login.

System superusers (employees with an access level of 0) can enable or disable the MFA function. To do this, go to Admin > Employees > Admin Page > Security > MFA, and amend the toggle on this page.

1. Download an authenticator app

On your phone, download an authenticator app (eg Microsoft Authenticator or Google Authenticator) from the iOS or Android app store. Your IT team may recommend a specific app.

2. Setting up MFA for your user

Once a superuser has enabled the MFA function, users will be redirected to a page to set up their MFA upon their next login. This step is mandatory and cannot be bypassed. On the setup page:

  1. Scan the QR code using the authenticator app installed in Step 1

  2. A row named 'SME Professional' will be added to your app, displaying a 6-digit authentication code that regenerates every 30 seconds

  3. Enter the code displayed in the app into the Authenticator code field in SME Professional (without spaces)

  4. Click Submit

3. Resetting MFA for a user

If a user is not able to access the system with their access code, a superuser (user with access level 0) can reset the MFA function for that user.

  1. Go to Admin > View all employees

  2. Click the edit pencil against the required user

  3. Select User settings

  4. Locate the Multi-Factor authentication section and click the Reset button
    ​

Upon their next login, the user will be redirected to a page to set up MFA again, as listed above in step 2.
​

4. Using MFA with branch switching

Where MFA is enabled on a system with branch switching set up, users will not be prompted to input their MFA code when switching between any linked systems.

For information on configuring additional security features, including setting an IP allowlist, click here.

Did this answer your question?