Summary
Multi-factor authentication (MFA) adds an extra layer of security by requiring a verification code from an authenticator app in addition to your password. In MirrorWeb Insight you set up MFA by scanning a QR code with your authenticator app and entering the code it generates. You can enable MFA yourself from your User profile, and some organisations require MFA, in which case you are prompted to set it up when you sign in.
Prerequisites
Email and password login credentials for MirrorWeb Insight (MFA setup is shown for password accounts; SSO users authenticate through their identity provider)
A mobile device with an authenticator app installed that generates one-time codes
Step-by-Step Instructions
Step 1: Start MFA setup
You can begin MFA setup in two ways:
From your profile: open the user menu (top right), select User Profile, and in the Multi-factor authentication section select Enable on the Authenticator app option.
When prompted at sign-in: if MFA is offered or required for your organisation, a page asks "Setup multi-factor authentication?" — select Enable MFA to continue. (If it is offered rather than required, you can choose Configure later.)
Step 2: Select your authentication method
On the multi-factor authentication page, the Authenticator app method is selected. Select Continue to proceed.
Step 3: Scan the QR code
MirrorWeb Insight displays a QR code with the instruction: "Scan the QR code with your authenticator app and enter the verification code below."
Open your authenticator app.
Add a new account and scan the QR code shown on screen.
If you cannot scan the code, select Copy QR key to copy the key and enter it manually in your authenticator app. (The button changes to QR key copied after you select it.)
Step 4: Enter the verification code
Your authenticator app generates a six-digit code.
Enter the code into the six-box code field on the MFA screen.
Select Submit.
If the code is incorrect, the message "Invalid passcode" is shown so you can try again.
Notes
Note: MirrorWeb Insight supports authenticator-app MFA. (An SMS option exists in the interface but is currently disabled.)
Note: You can only have one MFA method enabled at a time. To change methods, use the Multi-factor authentication section of your User profile.
Note: If MFA is enforced by your organisation, you cannot deactivate it from your profile — the system reports that "MFA is enforced by one or more of your organizations."