Multi-factor authentication

Multi-Factor Authentication (MFA) or Single Sign-On (SSO) secures accounts and protects sensitive data. Setting up MFA or SSO is required to access the PPRO Dashboard.

MFA protects accounts by requiring a secondary verification step during login. This prevents unauthorized access even if credentials are compromised.

Overview

The PPRO Dashboard requires 2 factors of authentication during sign-in:

  1. Password: Primary credentials.
  2. Verification Code: A time-based 6-digit code from an authenticator application.

Alternatively, organizations can manage authentication through an external identity provider using SSO.

Setting up MFA

Configure an authenticator app the first time you sign in, go to Access for information about logging in and resetting your password. If you need to link a new device later, go to Resetting or Configuring a New Authenticator App to learn how a new device gets added after initial setup.

Step 1: Get an authenticator app

Download and install an authentication app on a mobile phone. Popular options include:

Many password managers, such as 1Password or Keeper, can act as an authenticator app for MFA if downloading an app isn't possible.

Step 2: Link the authenticator app

  1. Log in to the PPRO Dashboard using an email address and password and a step by step guide with a QR code is shown.
  2. Open the authenticator app on the mobile device.
  3. Select the option to add a new account or scan a QR code (typically a "+" symbol or a Scan QR code button).
  4. Scan the QR code on the computer screen using the device camera. The app automatically recognizes and processes the code.
📘

Manual configuration

If the camera cannot scan the QR code, authenticator apps allow users to manually set up an account. You needs to:

  1. Click on “Show secret key” next to the QR code.
  2. Select the option to manually add a new account.
  3. Copy and paste or type the secret key into the authenticator app.

Step 3: Complete verification

  1. Locate the 6-digit verification code generated by the authenticator app.
  2. Enter this code into the Enter code field on the login screen.
  3. Click "Verify"

Subsequent logins require entering a 6-digit code from the configured authenticator app.

Resetting or Configuring a New Authenticator App

To link a new device, go to your profile page and select "Reset authenticator app". A warning modal opens:

You'll be taken to set up a new authenticator app. Complete this now. If you leave without finishing, your current authenticator app will stay linked.

Selecting Reset app unlinks the current device right away and opens the setup dialog immediately. There’s no gap where MFA is turned off. The setup dialog can’t be dismissed until a new authenticator app is linked and verified, so treat this as a single, uninterrupted action rather than two separate steps.

If a lockout occurs due to MFA issues or lost authenticator app access, contact an account administrator to reset the device on your behalf (see Resetting a Device for Other Users). At your next sign-in after an admin reset, you’ll be asked for a one-time password sent to your email (valid for 3 minutes) instead of a code from your authenticator app. Once that’s verified, you’ll be prompted to set up a new authenticator app — until setup is complete, you’ll only be able to access your profile page.

Resetting a Device for Other Users

Only account administrators can perform this action.

  1. Navigate to the user management section in the PPRO Dashboard.
  2. Select the target user profile.
  3. Click "Reset authenticator app" button.

A warning modal opens:

This unlinks the authenticator app currently set up for [user]'s multi-factor authentication.

Verify the user’s identity through a secondary channel before continuing.

The next time they log in, they’ll receive a one-time password by email to verify their identity, then be prompted to set up a new authenticator app.

Selecting "Reset app" clears linked authenticator app immediately. At their next sign-in, the user authenticates with the emailed one-time password instead of their authenticator app, then must set up and verify a new authenticator app. Until they do, they can only access their profile page — other Dashboard functionality stays blocked.



Did this page help you?