Two-factor authentication (2FA)
Two-factor authentication (2FA) adds an extra layer of security to the sign-in process in CheckBiz360. Once activated, access to the account requires not only the user's password but also a verification code generated by an application on their mobile device.
This measure significantly reduces the risk of unauthorised access, even if an employee's password is compromised. Activating it is particularly advisable for profiles with a high access level, such as managers and owners.
How two-factor authentication works
When the employee activates 2FA, every time they sign in to CheckBiz360 they must complete two steps:
- Enter their usual email and password.
- Enter a 6-digit numeric code generated by their authenticator application.
The code is valid for a short interval (generally 30 seconds) and regenerates automatically. This design guarantees that even if somebody obtains the password, they cannot get in without also having the employee's physical device.
Setting up 2FA from the application
Step by step for the employee
- Sign in with your credentials: in the mobile app, from the profile section; in the back office, from My account.
- Find the security section of your account.
- Enable the Two-factor authentication option.
- The platform will generate a QR code and a manual secret key.
- Open your authenticator application (see options in the next section) and add a new account.
- Scan the QR code with your device's camera or, if you prefer to enter it manually, copy the secret key shown on screen.
- The authenticator application will start generating 6-digit codes automatically.
- Enter the current 6-digit code on the CheckBiz360 verification screen and press Confirm.
2FA will be active from that moment on.
Compatible authenticator applications
CheckBiz360 is compatible with any application that implements the TOTP (Time-based One-Time Password) standard. The most common are:
- Google Authenticator — Available for Android and iOS.
- Microsoft Authenticator — Available for Android and iOS.
- Authy — Available for Android, iOS and desktop. Supports encrypted cloud backups.
Trusted devices
During the 2FA verification process, the application may offer the option of marking the current device as a trusted device. This option means the system will not ask for the 2FA code on subsequent sign-ins from that same device, for a configured period of time.
Trusted devices are useful for employees who habitually work from the same phone or tablet and do not want to enter the code on every access.
Enabling or disabling 2FA from the back office
The company's managers can manage any employee's 2FA status directly from the back office, without the employee having to be involved:
- Sign in to the back office with manager or owner credentials.
- Go to Employees and open the employee's profile.
- In the Security section, find the Two-factor authentication control.
- Enable or disable the switch as appropriate.
- Save the changes.
Recovering access if the device is lost
If an employee loses the device on which they had set up 2FA and cannot generate the verification code, the recovery process is as follows:
- The employee contacts their manager or owner.
- The manager goes into the back office and temporarily disables 2FA on the employee's profile.
- The employee signs in with their usual password without needing a code.
- Once inside, the employee sets up 2FA again with their new device, following the steps described above.
- The manager can re-enable the 2FA requirement once the reconfiguration is complete.
Who can manage other employees' 2FA
Enabling and disabling 2FA from the back office is available to the manager (level 3) and owner (level 4) roles. Employees can set up their own 2FA from the mobile application regardless of their role.