What is Two Factor Authentication?
Two factor Authentication (TFA), sometimes called Multi-factor Authentication (MFA), is the process of having an extra code to enter to verify that you're the one using your username and password for the website.
This means that if anyone gets your login credentials, they're useless unless they have the extra randomly-generated code (which they won't because it'll be on your phone only).
To set up TFA on your website:
On your computer/laptop:
- Go to the Admin Panel for your website. This is typically your full gov.uk domain name plus a "/admin" at the end.
- Enter your Username and Password as normal and click Login
- Hover over the Profile icon in the top-right
- Click Edit Profile
- Scroll down the page to the "Two-factor authentication settings" section
- Click Configure 2FA
On your phone:
- Unlock your phone and open the OneAuth app
- Use your fingerprint to verify in if prompted
- Make sure the correct account is selected (this is only relevant if you clerk for multiple councils)
- Click the Authenticator button at the bottom.
- Click Add New
- Scan the QR code on your computer screen with your phone.
- Click Done
Back on your computer/laptop:
- Click the I'm Ready button
- Type in one of the 6 digit codes that's cycling on your phone into the Verification Code box (Hint: if the numbers go red then they're about to expire, wait for a few seconds for a new code (in green) to give you plenty of time to type the numbers in).
- Click Validate and Save
- Click Generate Backup Codes (these are important in case you ever lose your phone)
- You can either:
- Copy them to a Word/Notepad document and save them on your computer or on your Cloud Storage.
- Print them so you have a paper copy
- Send the codes by email (not recommended)
- Click I'm Ready, Close the Wizard
And that's done!
When you next log in, enter your username and password as normal, then go to your OneAuth app and enter one of the green codes you see in the Authenticator section.