Skip to main content

Two-factor authentication

What this is​

Two-factor authentication (sometimes called 2FA or MFA) adds a second check when you sign in. After your password, ConsignTrak asks for a 6-digit code from an authenticator app on your phone: Google Authenticator, Microsoft Authenticator, 1Password, Authy or similar. Someone who steals your password still can't get in without your phone.

Today it applies to Administrator accounts, because they can change everything. Other roles sign in with a password only.

Before you start​

  • Role: Administrator.
  • Settings: your warehouse must require two-factor authentication for administrators. That's a server setting chosen when ConsignTrak is installed, not something on the Settings screens. If it's off, you won't be asked to set it up, and there's no button to turn it on yourself (tracked in issue #1476).
  • You'll need: a phone with an authenticator app installed, and somewhere safe to keep 10 recovery codes (a password manager, or a printed copy in a locked drawer).

Step by step​

Setting it up (once)​

When two-factor authentication is required and you haven't set it up, the next time you sign in ConsignTrak takes you to Set up two-factor authentication before anything else.

  1. Open your authenticator app and choose to add an account (usually a + button).

  2. Scan the QR code on the screen with the app. If you can't scan, choose the app's "enter a setup key" option and type the code shown under Or enter manually.

  3. Type the 6-digit code the app now shows into 6-digit code.

  4. Choose Verify and enable.

  5. Save your recovery codes. The next screen, Save your recovery codes, shows 10 codes. Use Copy, Download .txt or Print to keep them.

    You only see these once

    ConsignTrak shows the recovery codes one time and never again: "Save these now. They will not be shown again." Each code gets you in once if you lose your phone. Without them, only an administrator can get you back in.

  6. Choose I have saved them — continue. You're signed in.

Signing in with a code (every time)​

  1. Sign in with your username and password as usual (see Signing in).
  2. Open your authenticator app and find the ConsignTrak entry. The code changes every 30 seconds.
  3. Type the current code into 6-digit code on the Enter your code screen.
  4. Tick Trust this device for 30 days if this is your own computer. ConsignTrak won't ask for a code on this browser for 30 days. Leave it unticked on a shared computer.
  5. Choose Verify. You land on the dashboard.

If you don't have your phone​

  1. Choose Use a recovery code instead on the Enter your code screen.
  2. Type one of your saved recovery codes into Recovery code. They're 10 characters long.
  3. Choose Verify. You're signed in, and that code is used up.
  4. Get new codes once you have your phone back, from Your account.

Back to authenticator code returns you to the 6-digit code screen.

There are no screenshots of these screens: they can only be reached by an account that's mid-setup, and the demo system used for this manual doesn't require two-factor authentication.

Every field and option​

Set up two-factor authentication

Field or controlWhat it meansRequiredDefaultWhat changes when you set it
Set up two-factor authentication (heading)You're connecting an authenticator app.———
QR codeScan it with your authenticator app to add ConsignTrak.———
Or enter manuallyThe same secret as text, for apps that can't scan.———
6-digit codeThe code your app shows after adding ConsignTrak. Proves the app is set up correctly.YesBlank—
Verify and enableChecks the code and turns two-factor authentication on.——Takes you to your recovery codes.

Save your recovery codes

Field or controlWhat it meansRequiredDefaultWhat changes when you set it
Save your recovery codes (heading)Your 10 one-time backup codes.———
CopyCopies all 10 codes to the clipboard.———
Download .txtSaves the codes as a text file.———
PrintPrints the codes.———
I have saved them — continueLeaves the page and opens the dashboard.——The codes are never shown again.

Enter your code

Field or controlWhat it meansRequiredDefaultWhat changes when you set it
Enter your code (heading)The second step of signing in.———
6-digit codeThe code currently showing in your authenticator app.YesBlank—
Trust this device for 30 daysSkip the code on this browser for 30 days.NoOffAdds this browser to Trusted devices on your account.
VerifyChecks the code.——Signs you in.
Use a recovery code insteadOpens the recovery-code screen.———

Use a recovery code

Field or controlWhat it meansRequiredDefaultWhat changes when you set it
Use a recovery code (heading)Signing in without your phone.———
Recovery codeOne of the 10-character codes you saved.YesBlank—
VerifyChecks the code.——Signs you in and uses up that code.
Back to authenticator codeReturns to Enter your code.———

Turning two-factor authentication off, new recovery codes and trusted devices are on the Account security page: see Your account.

What happens next​

  • Every future sign-in asks for a code, except on browsers you trust.
  • Account security shows the date you turned it on and how many unused recovery codes you have left.
  • Each code, success or failure, is recorded in the audit trail.

Common problems​

"That code didn't match. Try again." — The code was mistyped or had already changed. Wait for a fresh code and type it promptly. If codes never work, check your phone's clock is set automatically: authenticator codes depend on the right time.

"That code didn't match or has already been used." — That recovery code is wrong or was used before. Each works once. Try another.

"Account locked due to repeated authentication failures. Contact an administrator." — Three wrong codes in a row (authenticator or recovery) lock the account. Another administrator must choose Unlock account on your user record. See Users & roles.

"Too many enrollment attempts. Please wait and try again." — Too many wrong codes during setup. Wait a few minutes and sign in again to restart.

I lost my phone and my recovery codes. — Ask another administrator to choose Reset MFA on your user record. Next time you sign in, you set it up from scratch with your new phone. If you're the only administrator, contact whoever installed ConsignTrak for you.

I got a new phone. — Sign in once with a recovery code, then ask an administrator to Reset MFA so you can set it up on the new phone. Or, if you still have the old phone, turn two-factor authentication off on Your account and you'll be asked to set it up again at your next sign-in.

Watch the video​

A4 · Turning on two-factor authentication — this episode is not recorded yet.
Will cover: Enable MFA, use a code, recovery codes
See all training videos