A password alone is easy to guess, reuse or share. Two-step verification adds a one-time code from your phone, so a stolen password is not enough to sign in.
Turn on two-step verification
- Sign in and open
Profile > Security. - Click Enable two-step verification.
- Scan the QR code with an authenticator app such as Google Authenticator or Microsoft Authenticator. If you prefer, choose SMS codes to your registered mobile number.
- Enter the six-digit code to confirm.
- Download your backup codes and keep them somewhere safe, away from your phone.
From now on, you enter a code after your password whenever you sign in on a new device.
Make it mandatory for your team
The account owner can require two-step verification for all admins, or for every user, from Settings > Security. Anyone without it is asked to set it up at their next sign-in.
Password habits that work
- Use at least 12 characters. A short sentence is easier to remember than random symbols.
- Never reuse a password from email, banking or social media.
- Give every staff member their own login. Never share one account at the front desk.
- Use a password manager for the whole team.
- Deactivate users on the day they leave.
What we do on our side
Passwords are stored as one-way hashes, sign-in is blocked after repeated failed attempts, and idle sessions sign out automatically. Every sign-in is recorded in the audit log.
Locked out completely? Raise a ticket from another admin's login, or contact us.