Two-Factor Authentication
Add an extra layer of security to your account with two-factor authentication (2FA).
What is 2FA?
Two-Factor Authentication requires two forms of verification:
- Something you know - Your password
- Something you have - A code from your authenticator app
Even if someone steals your password, they can’t access your account without the second factor.
Why Use 2FA?
- Prevents unauthorized access - Password alone isn’t enough
- Protects sensitive data - Client and financial information
- Compliance - May be required by regulations
- Peace of mind - Know your account is secure
Setting Up 2FA
Prerequisites
Install an authenticator app on your phone:
- Google Authenticator (iOS/Android)
- Authy (iOS/Android/Desktop)
- Microsoft Authenticator (iOS/Android)
- 1Password (if you use it for passwords)
Step-by-Step Setup
- Go to Settings > Security
- Find Two-Factor Authentication section
- Click Enable 2FA
- A QR code appears on screen
- Open your authenticator app
- Tap Add Account or +
- Scan the QR code
- Enter the 6-digit code shown in the app
- Click Verify
- Save your backup codes
Backup Codes
After enabling 2FA, you’ll receive backup codes:
XXXX-XXXX-XXXX
XXXX-XXXX-XXXX
XXXX-XXXX-XXXX
...Important:
- Save these in a secure location
- Each code can only be used once
- Use them if you lose your phone
Logging In with 2FA
After entering your password:
- Open your authenticator app
- Find Zettabit entry
- Note the current 6-digit code
- Enter the code before it expires (30 seconds)
- Click Verify
If You Lose Your Phone
Use a backup code:
- Enter your email and password
- Click Use Backup Code
- Enter one of your saved backup codes
- Login successful
Then immediately:
- Disable 2FA
- Set up 2FA again with new device
- Generate new backup codes
Disabling 2FA
To turn off 2FA:
- Go to Settings > Security
- Click Disable 2FA
- Enter your password to confirm
- 2FA is now disabled
Only disable temporarily for troubleshooting. Re-enable for security.
Regenerating Backup Codes
If you’ve used backup codes or think they’re compromised:
- Go to Settings > Security
- Click Regenerate Backup Codes
- Enter your current 2FA code
- New codes are generated
- Old codes are invalidated
Troubleshooting
”Invalid verification code”
- Ensure you’re entering the current code (they change every 30 seconds)
- Check your phone’s time is correct (auto-sync recommended)
- Make sure you’re using the right account in your app
”2FA code expired”
Codes are valid for 30 seconds. Enter the new code that appears.
Phone time is wrong
Authenticator apps depend on accurate time:
- Go to phone Settings
- Enable automatic date/time
- Restart authenticator app
Lost phone and no backup codes
Contact your administrator. They can temporarily disable 2FA for your account after verifying your identity.
Admin: Managing User 2FA
Administrators can:
View 2FA Status
See which users have 2FA enabled in the Users list.
Require 2FA
Enforce 2FA for all users or specific roles:
- Go to Settings > Security
- Enable Require 2FA for all users
- Users without 2FA must set it up on next login
Reset User 2FA
If a user is locked out:
- Go to Users
- Find the user
- Click Reset 2FA
- User can set up 2FA again
Best Practices
- Always enable 2FA - Especially for admin accounts
- Use a secure authenticator - Avoid SMS-based 2FA when possible
- Store backup codes safely - Password manager or secure location
- Don’t share codes - They’re for your use only
- Update recovery options - Keep email and phone current