You are here: start » en » Internal Documentation » faq » Setting up two-factor authentication

Setting up two-factor authentication

This page explains how to protect your user account in this wiki with a second factor (two-factor authentication, 2FA for short) — and what is different about signing in afterwards.

Prerequisites

Two methods are available. You may set up both at once, and that is also the recommendation — see the note at the end of this section:

  • Authenticator app (recommended) — for example Microsoft Authenticator, Google Authenticator, Aegis or a comparable app on your smartphone.
  • Email — uses the email address held for you in the wiki. This option is visible only if your administrator has released it.
The authenticator app is the safer method: the code is calculated locally on your device, independently of your email mailbox. The email method is deliberately meant as the simpler but weaker alternative — the code depends here on the same mailbox that is often used for other password resets as well.

Setting it up

Open your profile for this (User Profile in the top navigation, address doku.php?do=profile). The set-up is in the “Two-factor authentication (TOTP)” section.

With an authenticator app

  1. Click “Set up two-factor authentication”.
  2. The page now shows a QR code and, underneath it, the same key as text.
  3. Open your authenticator app and add a new account (usually “+” or “Add account”).
  4. Scan the QR code — or enter the text key manually if scanning is not possible.
  5. The app now shows a 6-digit code that changes every 30 seconds.
  6. Enter the code currently displayed into the “Confirmation code” field and click “Confirm and enable”.

Only after this confirmation is the set-up complete — a QR code that has not been confirmed activates nothing.

With email

  1. Click “Set up by email”.
  2. A confirmation code is sent to the email address held for you in the wiki.
  3. Open your mailbox, enter the 6-digit code into the “Confirmation code” field and click “Confirm and enable”.
  4. If the code has not arrived or has expired: click “Send code again”.

Signing in after set-up

As soon as your administrator has enabled two-factor enforcement for your account, signing in runs in two stages:

  1. Enter user name and password as usual.
  2. A page “Two-factor confirmation” appears.
  3. With the authenticator app: enter the current 6-digit code from the app and click “Confirm”.
  4. With email: first click “Send code by email”, enter the code you receive, then click “Confirm”.
As long as you have not set up a second factor, nothing about your sign-in changes — the second stage appears exclusively for accounts that already have one.

There are no backup or recovery codes. Neither printed nor displayed, neither at set-up nor later — there is nothing you have failed to keep. What applies instead once the app is gone is set out in full on Authenticator lost or phone broken – recovering your account. That page is readable without signing in and can therefore still be opened at the moment you cannot get in.

The most effective protection against that case costs two minutes, now. Set up the code by email in addition to the app, provided the Set up by email button appears in your profile. Both factors may exist at the same time, and one of the two is then enough at sign-in — a lost phone no longer locks you out. After the fact, with the app lost, this can no longer be done.

Frequently asked questions

I have lost my phone or changed it

That depends on whether you are still signed in somewhere: on a device that is still signed in you replace the factor yourself in your profile; if you are not signed in anywhere any more, an administrator resets it. Both routes with every step: Authenticator lost or phone broken – recovering your account.

Resetting your password does not help in this case — it leaves the second factor unchanged, and the code prompt appears afterwards just the same.

The code from my app is not accepted
  • Check whether the time on your phone is correct (switch on automatic time synchronisation).
  • Wait for the next code (it changes every 30 seconds) and try again.
The email with the code does not arrive
  • Check your spam folder.
  • Use “Send code again”.
  • If nothing still arrives: contact an administrator — outbound mail may currently be unavailable on this instance.
Can I use both methods at once?

Yes. An account may hold the authenticator app and the code by email at the same time; in your profile each method has its own status and its own disable box. At sign-in one of the two codes is then enough — there is only one input field, and both methods are checked against it.

That is precisely the only real fallback route this wiki knows, and it has to be set up beforehand. See Authenticator lost or phone broken – recovering your account, section “The code by email — what it is and what it is not”.

I cannot get in at all any more

Authenticator lost or phone broken – recovering your account answers this case in full and is readable without signing in.


wiki 2fa totp email signin profile

en/wiki/faq/two-factor.txt · Last modified: by 127.0.0.1