Logging in with Two-Factor / Multi Factor Authentication
A simple guide to logging in securely when two-factor / multi-factor authentication is switched on for your candidate account.
I want to:
- Understand what two-factor authentication is and why it is used
- Log in using a secure email link
- Set up and log in with an authenticator app
- Log in if I lose access to my authenticator app
- Turn off two-factor authentication or get new recovery codes
What is two-factor authentication
Two-factor authentication (2FA) - also known as multi factor authentication (MFA) - adds a second security check when you log in, on top of your password. After you enter your username and password, you complete one more step to prove it is really you. This helps protect your account against unauthorised access and keeps your personal data safe.
Depending on how the organisation you are applying for uses two-factor authentication and how your account is set up, this second step is either:
- A secure link sent to your email address, or
- A code from an authenticator app on your phone
|
Good to know If you log in using a social or single sign-on option (such as your organisation's account), you will not see these extra steps, as that sign-in method already includes its own security check. |
Logging in with a secure email link
If your account uses email link login, you receive a one-time link by email each time you log in. Select the link to complete your login. Each link is unique to your login attempt, expires after 5 minutes, and can only be used once.
Steps to log in
- Go to the login page and enter your username and password as usual.
- You will see a screen confirming that a link has been sent to your email address.
- Open your email inbox and find the login email.
- Select the link in the email. You are taken back to your browser and logged in automatically.
- The link must be opened in the same browser that requested it. If you are trying to sign in on your PC, you cannot open the link on your phone.
|
Important The login link expires after 5 minutes and can only be used once. If you request a new link, any earlier link stops working. |
If you cannot find the email
- Check your spam or junk folder, and refresh your inbox.
- Wait for the on-screen timer to count down.
- When it reaches zero, select Click here to resend the email to send a new link.
- Check the time in the newest email so you open the most recent link.
If your link does not work
If you select a link that has expired or is no longer valid, you will see this message:
"Sorry, the link you used is invalid. This could be because it has expired or may not be the latest link."
To fix this, close any open tabs for the site, then go back to the login page and log in again to request a fresh link.
Logging in with an authenticator app
An authenticator app creates a short code that changes every 30 seconds. You enter the current code to finish logging in. Depending on how your account is set up, you may be required to set this up, or given the choice to skip it for now.
Setting up an authenticator app
You need an authenticator app on your phone before you start. Common free apps include Google Authenticator, Microsoft Authenticator and Authy.
After creating or entering your password, you will see a screen asking you to set up an authenticator app.
|
Good to know Setting up an authenticator app for two-factor authentication (2FA) may be optional, depending on how the organisation has set things up. If you are offered the choice, you can select Continue without setting up an authenticator app to skip this step. If you skip it, you will keep using the secure email link for your 2FA checks instead. |
- Open your authenticator app and use it to scan the QR code shown on screen.
- Your app displays a six-digit verification code.
- Enter that code in the box on screen and select Verify.
Saving your recovery codes
When you set up an authenticator app, you are shown a list of six one-time recovery codes. These let you log in if you ever lose your phone or lose access to your app, so keep them safe.
- Copy or write down all six recovery codes and store them somewhere secure.
- Select Continue to confirm you have saved them.
|
Important Each recovery code works only once. Treat them like passwords and do not share them with anyone. |
Logging in with your code
- Enter your username and password on the login page.
- When prompted, open your authenticator app and read the current six-digit code.
- Enter the code in the box and select Login.
If you lose access to your authenticator app
If you cannot use your authenticator app, for example if you lose or change your phone, you can log in with one of the recovery codes you saved earlier. Each recovery code works only once.
- On the code entry screen, select Lost access to your device? Click here to login another way.
- Enter one of your saved recovery codes and select Login.
- Once you are logged in, we recommend resetting your two-factor authentication and generating new recovery codes.
Managing two-factor authentication in your account
You can manage your two-factor authentication from the Sign in details section of your account page. From here you can turn off 2FA or generate a fresh set of recovery codes.
Turning off two-factor authentication
Select Disable Two Factor Authentication to turn off authenticator app login for your account.
Getting new recovery codes
Select Generate new Recovery Codes to create a fresh set of codes. Your previous codes stop working, so save the new ones somewhere secure.
FAQs
Why am I being asked for a second step to log in?
Two-factor authentication has been turned on for your account to keep it more secure. It helps make sure that only you can access your personal details.
I did not try to log in but received a login email.
You can ignore the email if you did not try to log in. If you keep receiving login emails you did not request, we recommend changing your password.
Do I need to complete the extra step every time?
If you use email link login, you receive a link each time you log in. If you use an authenticator app, you enter a code each time. If your session times out whilst you are still using it, you may be able to sign back in with just your password.