This article explains how Multi-Factor Authentication (MFA) works in Assure and how to set it up. MFA adds a second verification step to the standard username and password login by emailing the user a 6-digit one-time passcode. MFA applies only to username and password authentication; it is not available for SSO logins. MFA can be enabled independently for the main Assure web application and for AssureGO+ (the Evotix mobile Progressive Web Application). Enabling MFA requires the Evotix Support Team to activate the feature, all users to hold unique email addresses, and Login Management to be configured in System Settings. System Administrators can generate an MFA code on behalf of a user if the user cannot access their email.
Prerequisites
- MFA must be enabled by the Evotix Support Team. Raise a ticket through the Evotix Support Portal to request MFA to be activated. MFA cannot be self-enabled by customers.
- Users must have unique email addresses. MFA uses the email address linked to each user profile to send the one-time passcode. Duplicate email addresses will prevent MFA from functioning correctly.
- Login Management must be enabled. Navigate to Settings > System Configuration > System Settings > Password and Login Management and tick the Use Login Management checkbox.
Overview
- The main Assure web application
- AssureGO+ (the Evotix mobile Progressive Web Application)
Note: Enabling MFA for AssureGO+ applies the requirement across all AssureGO+ Portal Dashboard instances. Consider whether your AssureGO+ users will have access to their email account when working on site before enabling MFA for AssureGO+.
- Lock user account after this many failed login attempts - Set the maximum number of incorrect password or MFA code attempts before the account is locked. The maximum is 10 attempts.
- During this number of minutes - Specify the time window within which failed attempts are counted.
- Number of minutes to suspend account for - Define how long an account remains locked after too many failed attempts.
- Email address to notify when a user account is locked - Enter an email address (typically a System Administrator's) to receive a notification whenever an account is locked. System Administrators can manually unlock user accounts via User Management.
AI Metadata
- Product Area: Authentication, System Configuration, Password and Login Management, User Management
- User Role: System Administrator (setup and troubleshooting); All Assure Users (login experience)
- Tags: Multi-Factor Authentication, MFA, two-step verification, one-time passcode, OTP, Login Management, Assure security, AssureGO+, user authentication, account lockout, email verification, unique email
- Version/Region: All Assure versions; all regions. MFA must be enabled by Evotix before use.
- Important Synonyms: MFA = Multi-Factor Authentication = Two-step Verification = Two-factor Authentication; One-time passcode = 6-digit code = OTP; AssureGO+ = Assure mobile app = Assure PWA; Login Management = account lockout settings; System Administrator = Admin; Evotix Support Portal = support ticket
- Suggested Embedding Keywords: enable MFA Assure, multi-factor authentication Assure login, two-step verification Assure, Assure 6-digit code login, MFA one-time passcode, Login Management MFA, AssureGO+ MFA, admin generate MFA code, Assure unique email MFA, account locked MFA Assure, re-send verification email Assure
- Relevant Modules and Cross-Module Implications: This article is scoped to the System Configuration area of Assure, specifically Password and Login Management within System Settings. MFA applies globally to all Assure users and, when separately enabled, to all AssureGO+ users across all Portal Dashboard instances. MFA applies only to username and password authentication and is not applicable where Single Sign-On (SSO) is in use. The Login Management settings configured alongside MFA (account lockout, failed attempt limits) apply system-wide and affect all module access. Account unlocking is managed via User Management (Settings > Organisational Configuration > Users).