Turning on two step verification
Short answer: open My profile and click the button in the Security block to set up two-step verification. Scan the QR code with an authenticator app, confirm with the six-digit code your app shows, and then save the ten recovery codes you're given.
Step by step
- Click your avatar at the bottom left and choose My profile.
- Scroll to the Security block at the bottom and click the button to set up two-step verification.
- Scan the QR code with your authenticator app. Microsoft Authenticator, Google Authenticator and 1Password all work.
- Enter the six-digit code your app shows. Only after that confirmation is two-step verification really on.
- You're shown ten recovery codes. Save them somewhere safe and confirm that you did.
The code in your app changes every thirty seconds and is calculated on your own device. So no SMS or email is involved, and it works even when your phone has no internet connection.
Do save those recovery codes
This is the part people get caught out on later. You see those ten codes once, on that one screen. They're nowhere else and you can't retrieve them afterwards. That's why you can't dismiss that screen without confirming you've saved them.
Close it without writing them down anyway and your only way out is generating a new set. Feel free to do that, but know that the old codes expire the moment you do, including the ones you hadn't used yet. The same goes for turning two-step verification on again: every time you get a fresh set, and codes from a previous pairing do nothing.
What changes when you sign in
From now on every sign-in route ends on the same second step. Whether you use your password, a code from your email, or a sign-in link, Sarrai always asks for the code from your app afterwards.
So the sign-in link does not exempt you. That's deliberate: anyone with access to your mailbox can request a link themselves, and if that route skipped the second step, two-step verification would no longer protect your account.
Enter a wrong code five times and your account locks for fifteen minutes, just as it does with a wrong password.
Turning it off or re-pairing
You turn it off from the same Security block, and no code or password is asked for. That's on purpose: someone who has lost their app and gets in with a recovery code needs to be able to turn two-step verification off. Demanding a code would lock out exactly that person.
What happens then: your shared secret is discarded and your recovery codes expire. Turn it on again later and you scan a new QR code. The old entry stays in your authenticator app but no longer works, so remove it yourself.
New phone, or you suspect someone knows your secret? Use re-pair. That turns two-step verification off temporarily until you confirm the new code. Between those two steps your account is protected by your password alone, so do it in one go.
Good to know
Two-step verification is each user's own choice. Your administrator can't impose it on your whole workspace and can't turn it on for you either. Turning it off, if you're locked out, they can; see Turning off a colleague's two-step verification.
If you turn off your own two-step verification, no email goes out about it. When a colleague turns it off for you, one does. What you notice either way: turning it off signs you out everywhere.
Changing your email address on your profile doesn't touch your two-step verification. The pairing hangs off your account, and the name your app shows keeps your old address. That's only a label.
Also searched as
"turn on two-factor", "set up 2FA", "pair an authenticator", "how do I secure my account further", "where are my recovery codes", "scan QR code for Sarrai"
See also
Was this article helpful?
Your feedback helps us improve this article.
Thanks for your feedback!