The “Multi-factor” authentication Login

In today's digital landscape, the importance of robust security measures cannot be overstated. XoroERP supports Multi-Factor Authentication (MFA) to safeguard its users' accounts by implementing two-step authentication.

Multi-Factor Authentication (MFA) is a powerful security feature that adds an extra layer of protection to the login process. It requires users to provide at least two pieces of evidence to verify their identity, ensuring that even if one factor is compromised, the chances of unauthorized access are significantly reduced.

Users will be required to provide two or more authentication factors, which can include something they know (such as a password), something they have (such as a mobile device), or something they are (such as biometric data like fingerprints or facial recognition).

How It Works:

  1. Go to the Login page, enter your username and password, and click "Sign In".

  2. Select the preferred OTP (One Time Password) method for two-step verification.

    • If both email and phone are set up, all options are displayed.

    • If no phone number is registered, only the email option appears.

  3. Choose an option to sign in and hit "Proceed".

  4. On the next page, enter the security code sent to your email or phone.

  5. To avoid entering an OTP on future logins from the same browser, check the "Don't require OTP on this browser" option.

  6. You will be prompted to enter a device name.

  7. Enter the device name and click "Login" to log into the system.

  8. The device name and details will be saved under the "My Trusted Devices" module. Saving the device will eliminate the need for an OTP during subsequent logins from that device.

Please Note:

  • The OTP expires in 45 seconds.

  • If the information is deleted from “User Trusted Devices”, the browser will ask for the OTP again while logging in.

  • If the User’s Email or Phone number is updated, the authorization Code/OTP will be received on the updated email/phone number.

  • Phone number is mandatory in user information and User Upload if using the 2 Factor Authentication process.

Last updated

Was this helpful?