Two-factor authentication
Turn on 2FA with an authenticator app, save the backup codes (shown once only), and see how signing in changes afterwards.
Two-factor authentication (2FA for short) adds a second step at sign-in: after your password, Mountify asks for a 6-digit code from an app on your phone. The code changes every 30 seconds and is never emailed or texted — it’s generated inside the app itself. Even someone who learns your password can’t get in without your phone.
You switch it on from your own account, for your own account. It takes two minutes. The only real risk is losing both your phone and your backup codes — which is why §4 is the most important part of this article.
1. What you need
An authenticator app on your phone. Any app that supports standard codes works — Google Authenticator, Microsoft Authenticator, Authy, 1Password, Bitwarden, or whichever password manager you already use. Install it before you start.
Nothing else is needed: no SIM card, no second email, and no mobile data at the moment you sign in (the code is calculated offline).
2. Where to switch it on
- Click your avatar at the bottom of the narrow icon rail on the left.
- Choose User settings.
- You land in the Personal section. Scroll to the second card — Two-factor authentication. Under its heading it reads “Add a second step at sign-in with an authenticator app.”
- While it’s off you’ll see an Off badge, the line “Protect your account with an authenticator app.”, and an Enable button.
3. Step by step: connect the app
- Press Enable. A Set up two-factor authentication dialog opens, instructing you to “Scan the QR code with your authenticator app, then enter the 6-digit code.”
- Open the authenticator app and choose “add account” / “scan QR code”.
- Point the camera at the square code on screen. An entry called Mountify appears in the app, with your email beside it.
- If the camera can’t help (say you’re working on the phone and the code is on the same screen), use the manual route: under the QR code it says “Or enter this key manually:” with a long key and a Copy button. Copy it and paste it into the app as the “key” / “setup key”.
- The app now shows a rotating 6-digit code. Type the current one into the Code from the app field.
- Press Verify and enable.
If the code is wrong you’ll see “That code is incorrect — check your authenticator app.” Try the next code (wait for it to rotate) — you get 5 attempts, after which the setup restarts.
Setup has a deadline. The open dialog is valid for about 10 minutes. If you got distracted and see “Setup expired — start again”, close the dialog and press Enable again — you’ll get a fresh QR code. The entry already sitting in your app is now dead; delete it so you don’t confuse yourself.
Careful: until you’ve entered a code and pressed Verify and enable, nothing is switched on. That’s good news: an abandoned setup can’t lock you out. The flip side — scanning alone is not enough.
4. The backup codes are shown only once
Right after a successful enable, the dialog moves to a Save your backup codes step. Under the heading it reads “Each code works once. Keep them somewhere safe — they get you in if you lose the authenticator.” Below is a grid of codes, a Copy codes button, and the warning “These codes are shown only once.”
Do this before you press Done:
- Press Copy codes.
- Put them somewhere you’ll find without your phone — a password manager, a document in the cloud, or on paper in the till.
- Only then press Done.
The rules for the codes:
| Rule | Detail |
|---|---|
| When they’re shown | Exactly once, immediately after enabling |
| Can they be viewed again | No. There is no screen that will show them a second time |
| Each code | Works once; a used one is burnt |
| How to get new ones | Turn 2FA off and on again — a fresh set is issued then |
Note: if you missed saving them, don’t wait until you need them. Turn 2FA off and on again right now — you’ll get a new set of codes (and a new QR code for the app).
Occasionally, on a technical hiccup, instead of the grid you’ll see “Two-factor authentication is on. Backup codes couldn’t be generated — you can regenerate them later.” That means the protection is working but you have no backup codes. The fix is the same: turn it off and on again.
5. What signing in looks like afterwards
Every subsequent sign-in:
- You type your email and password and press Sign in.
- A Two-step verification screen appears, reading “Enter the 6-digit code from your authenticator app.”
- You type the code from the app into the six boxes. The check runs by itself once they’re full.
- If your phone isn’t to hand, press Use a backup code and type a backup code.
The sign-in screens are in English for both admin languages — see Sign in & password.
The errors here are:
| Message | What to do |
|---|---|
| That code is incorrect — check your authenticator app and try again. | Wait for the code to rotate and type the new one. Also check your phone’s clock |
| That backup code is incorrect or has already been used. | Try the next one on the list — used codes never work twice |
6. Enabling it ends your other sessions
When you switch 2FA on, Mountify ends your other active sessions. The reason: they were opened before the protection existed and never cleared the second step.
In practice: if you’re signed in on your phone and on the front-desk tablet, you’ll have to sign in again there — this time with a code. The session you enabled 2FA from stays.
This is also the only way in Mountify to “sign out everywhere” — see Log out & security.
7. Turning it off
- Open User settings → Personal.
- In the Two-factor authentication card (now badged On) press Disable.
- A confirmation appears — Disable two-factor authentication? — explaining “You’ll no longer be asked for a code at sign-in. You can enable it again anytime.”
- Confirm.
Done — you get “Two-factor authentication disabled”. No code is required to turn it off — being signed in is enough. Which is exactly why you shouldn’t leave your account open on a shared computer.
When you disable it:
- The entry in your authenticator app becomes useless — delete it so it doesn’t confuse you.
- The backup codes stop working.
- The next sign-in needs only email and password.
8. If you lost your phone
In order of preference:
- Use a backup code. On the sign-in screen press Use a backup code and type one of the ones you saved. You get in normally.
- Once you’re in, turn 2FA off and on again on the new phone — that also issues a fresh set of backup codes.
- If you use a syncing password manager (1Password, Bitwarden, Authy), the entry is already on the new device — just open the app.
- If you have neither the phone nor the backup codes, you cannot get in on your own. There is no “I forgot my code” button and no administrator who can remove 2FA for you. Contact Mountify support from the address you sign in with and describe the situation.
Which is why: save the backup codes now, not when the phone goes missing. And if you’re changing phones on purpose, disable 2FA on the old one and enable it on the new one.
9. Everyone switches it on for themselves
2FA is a personal decision and a personal setting:
- No administrator can require it. There is no workspace setting that forces it on the team.
- Nobody else can see it. Members does not show who has 2FA and who doesn’t.
- Nobody else can remove it. The owner cannot disable it for a colleague — not even after a lost phone.
- It belongs to the account, not the workspace. If you’re in two businesses, the code is asked for both — one account, one protection.
If you want the whole team using it, that’s a conversation and a house rule, not a switch in the app.
Common questions
Can the code come by SMS? No. Mountify sends no SMS. The code is generated in the app.
Can I use one app for several accounts? Yes. The entry is called Mountify with your email next to it, so it’s distinguishable from the rest.
The code is always “incorrect”. What’s wrong? Almost always a phone clock that has drifted. Turn on automatic time in your phone settings and try again.
Does it slow me down every time? Only on a new sign-in, not on every page.
Will enabling 2FA sign me out? Not from the session you’re in. From the others — yes (see §6).
Are there passkeys or fingerprint sign-in? Not at the moment. The available second step is a code from an authenticator app.
What’s next
- Sign in & password — what signing in with a second step looks like.
- Log out & security — what else keeps the account safe.
- Your profile details — the rest of the Personal section.
- Change your sign-in email — 2FA stays on after an address change.