Skip to main content

How to set up multi-factor authentication (MFA)

Enable and configure MFA for your MirrorWeb Insight account.

H
Written by Harriet Christie

Summary

Multi-factor authentication (MFA) adds an extra layer of security by requiring a verification code from an authenticator app in addition to your password. In MirrorWeb Insight you set up MFA by scanning a QR code with your authenticator app and entering the code it generates. You can enable MFA yourself from your User profile, and some organisations require MFA, in which case you are prompted to set it up when you sign in.

Prerequisites

  • Email and password login credentials for MirrorWeb Insight (MFA setup is shown for password accounts; SSO users authenticate through their identity provider)

  • A mobile device with an authenticator app installed that generates one-time codes

Step-by-Step Instructions

Step 1: Start MFA setup

You can begin MFA setup in two ways:

  • From your profile: open the user menu (top right), select User Profile, and in the Multi-factor authentication section select Enable on the Authenticator app option.

  • When prompted at sign-in: if MFA is offered or required for your organisation, a page asks "Setup multi-factor authentication?" — select Enable MFA to continue. (If it is offered rather than required, you can choose Configure later.)

Step 2: Select your authentication method

On the multi-factor authentication page, the Authenticator app method is selected. Select Continue to proceed.

Step 3: Scan the QR code

MirrorWeb Insight displays a QR code with the instruction: "Scan the QR code with your authenticator app and enter the verification code below."

  1. Open your authenticator app.

  2. Add a new account and scan the QR code shown on screen.

If you cannot scan the code, select Copy QR key to copy the key and enter it manually in your authenticator app. (The button changes to QR key copied after you select it.)

Step 4: Enter the verification code

  1. Your authenticator app generates a six-digit code.

  2. Enter the code into the six-box code field on the MFA screen.

  3. Select Submit.

If the code is incorrect, the message "Invalid passcode" is shown so you can try again.

Notes

Note: MirrorWeb Insight supports authenticator-app MFA. (An SMS option exists in the interface but is currently disabled.)

Note: You can only have one MFA method enabled at a time. To change methods, use the Multi-factor authentication section of your User profile.

Note: If MFA is enforced by your organisation, you cannot deactivate it from your profile — the system reports that "MFA is enforced by one or more of your organizations."

Did this answer your question?