Account Security - Turning on Multi-Factor Authentication
Overview
Multi-factor authentication (MFA), also called two-factor authentication (2FA) or two-step verification, asks people to prove who they are with something more than a password or a link. BetterUnite offers it in two places:
- Your team's sign-in: require every user on your BetterUnite account to use a second step when they sign in to the admin. This is set once for your whole organization.
- Guest pages: require event guests to verify a code before they can open their guest page. This is set for each event.
Require two-factor authentication for your team
When you enforce 2FA, every user on your account has to complete a second step each time they sign in. Users who haven't set one up yet are walked through it at their next sign-in.
Sign-in methods
Your team can use three kinds of second step. Each user sets up their own.
| Method | How it works | Allowed by "Authenticator app or passkey only" |
|---|---|---|
| Text message | A 6-digit code is texted to the user's phone each time they sign in. Messaging or data rates may apply. | No |
| Authenticator app | The user enters a 6-digit code from an app such as Google Authenticator, Microsoft Authenticator or 1Password. Works without cell service. See Set Up an Authenticator App. | Yes |
| Passkey | The user confirms with their face, fingerprint or device PIN. A passkey can replace both the password and the code. See Sign In With a Passkey. | Yes |
Users who set up an authenticator app also get 10 one-time recovery codes, which they can use to sign in if they lose their phone.
Turn on enforcement
- Go to Settings and open the Users tab.
- Click Security & 2FA.
- Turn on Enforce.
- Under Allowed methods, choose one:
- Any method: text message, authenticator app or passkey. Each user chooses. This is the easiest for your team to adopt.
- Authenticator app or passkey only. More secure, because text message codes can be intercepted.
- Click Save changes.
The setting takes effect the next time each user signs in. Anyone already signed in stays signed in until their session ends.
Note: If you see a prompt to unlock Multi-Factor Authentication when you click Security & 2FA, the feature isn't included in your current plan. Contact support@betterunite.com to add it.
What your team sees at their next sign-in
After entering their password, each user sees one of the following:
| The user has | With "Any method" | With "Authenticator app or passkey only" |
|---|---|---|
| Nothing set up yet | Chooses between an authenticator app (recommended) and text message, then sets it up | Sets up an authenticator app |
| A trusted phone number only | Enters a code sent by text | Enters a code sent by text one more time, then sets up an authenticator app |
| An authenticator app | Enters a code from the app | Enters a code from the app |
| A passkey | Confirms with the passkey | Confirms with the passkey |
A user who signs in with Sign in with a passkey on the login page skips the password and the second step, because the passkey already counts as both.
If a user belongs to more than one BetterUnite account, the strictest setting among those accounts applies to them.
Users can turn it on themselves
Even when your organization doesn't enforce 2FA, any user can add an authenticator app or a passkey from User Settings (click your name or picture in the top right corner). Once a user turns on an authenticator app, they're asked for a code every time they sign in.
Reset a user's two-factor authentication
If someone loses their phone and their recovery codes, an administrator can reset their 2FA:
- Go to Settings and open the Users tab.
- Open the user.
- Click Reset 2FA Status. This button appears when your organization enforces 2FA.
This removes the user's phone number, authenticator app, recovery codes and passkeys. They'll be asked to set up two-step verification again at their next sign-in.
Too many incorrect codes
After 5 incorrect codes in a row, verification is locked for that user for 15 minutes. They can try again after that.
Require MFA for guest pages
This setting protects each guest's personal event page (their guest link) so that only the guest can open it, even if the link is forwarded.
Who can turn it on
Event administrators who can edit event settings.
Turn it on for an event
- Open the event in the admin.
- Go to the Edit Event page.
- Find Enforce Multi-factor Authentication (MFA) for guest pages.
- Turn on Enforce.
- Save the event.
The change takes effect as soon as you save, for that event's guest pages only.
What guests see
- The guest opens their guest link as usual.
- If we don't recognize their device yet, they see a message asking them to verify their access, and click Start Verification.
- They choose to receive a code by Phone Number (text message) or Email, using the contact details on their registration, and click Send Code.
- They enter the code and click Verify my access. If the code doesn't arrive, they can click Resend a new code.
Once verified, the guest goes straight to their guest page. If verification fails, the guest page stays locked.
Note: Guest page verification uses text message or email codes only. Authenticator apps and passkeys are for your team's sign-in, not for guests.