Skip to content
English
  • There are no suggestions because the search field is empty.

Set up and manage Multi-factor authentication (MFA)

Add a second layer of security for the users in your Virtualbadge.io account.

Multi-factor authentication (MFA) adds an extra step when signing in. In addition to a password, each user confirms their identity with a one-time code, either from an authenticator app or via email. Even if a password is compromised, no one can access the account without that second factor.

Why enable it?

Your Virtualbadge.io account is where your team creates, manages, and issues digital badges and certificates. Requiring MFA protects those accounts and the credentials you issue if a password is ever compromised. We recommend enabling it for everyone in your organisation.

Supported methods:

  • Authenticator app (e.g. Microsoft Authenticator, Google Authenticator) 
    Always available and cannot be turned off at the organisation level.
  • Email
    A one-time code sent to the user's email address. This method is optional and can be switched on or off by an organisation admin.

A. How to enable MFA for your organisation

    1. Go to Settings → Users and Roles.
    2. Turn on Multi-factor authentication.
    3. In the confirmation dialog, select Require.

    Once enabled, MFA becomes mandatory for every user in your organisation who hasn't already set it up. There is no grace period, anyone not yet enrolled will be prompted to set it up on their next login. The confirmation dialog also shows how many users still need to enrol.

    What your users see when they enable MFA

    The next time an affected user signs in, they'll be guided through the setup process automatically.

    1. Set up an authenticator app

    On the Set up two-factor authentication screen, the user:

    1. Opens their authenticator app. If they don't have one, they can download a free app such as Microsoft Authenticator or Google Authenticator.
    2. Chooses Add account or Scan QR code in the app, then scans the QR code shown, or enters the setup key manually.
    3. Enters the 6-digit code from the app and selects Confirm.

    2. Save recovery codes

    After confirming, the user is shown a set of one-time recovery codes. Each code can be used once to sign in if they lose access to their authenticator app. The codes are shown only once, so they should be stored somewhere safe. The user then selects I've saved my codes, continue to finish.

     


    B. Using email as a 2FA method

    Email is an alternative sign-in method that allows users to receive a one-time code by email instead of using an authenticator app.

    To enable it:

    1. Go to Settings → Users and Roles (Allowed methods).
    2. Turn on Allow email as a two-factor authentication method.

    The authenticator app is always available. If both the app and email are enabled, sign-in uses the authenticator app by default. But they will have an option to authenticate via email also.


    Turning MFA off

    To stop requiring MFA for your organisation:

    1. Go to Settings → Users and Roles.
    2. Turn off the MFA requirement and select Disable in the confirmation dialog.

    Turn off email as a method

    To remove email as a sign-in option:

    1. Go to Settings → Users and Roles.
    2. Turn off Allow email as a two-factor authentication method and select Turn off.