MFA Methods Available
Enabling Prompt to Set Up MFA at Login
Enabling MFA for Your User Account
Removing MFA from Your Account
Auditing MFA Adoption
Resetting MFA for Other Users
Too Many Failed Authentication Attempts
FAQ
Multi-Factor Authentication (MFA)
Multi-Factor Authentication (MFA) strengthens security by requiring multiple verification methods to access an account. This reduces the risk of unauthorized access, even if a password is compromised. Apaleo supports two MFA verification methods: Time-Based One-Time Passwords (TOTP) generated through authentication apps or password managers, and Passkeys. Account admins can control which methods are available to users.
MFA is a user-specific security feature, meaning each user can enable or disable it for themselves.
Since MFA is applied at the user level, a user’s MFA credentials and TOTP remain the same across all accounts they can access.
MFA Methods Available
Currently, MFA can be set up using the following methods:
- TOTP via an authentication app (e.g., Authy, Google Authenticator)
- TOTP via password managers (e.g., 1Password, Bitwarden)
-
Passkey (e.g., Face ID, Touch ID, Windows Hello, or a device PIN)
Passkeys are always available as an MFA method and cannot be disabled by account admins. TOTP can be disabled if the account admin prefers passkeys as the only MFA option. For more information on setting up and managing passkeys, see Passkey Authentication.
Recommendations
- On computers and shared devices, use browser extensions of password managers that support TOTP or passkeys for seamless and secure authentication.
- During setup, verify your account and authentication method to prevent losing access or misconfigurations.
- Ensure your device's time is correctly synchronized with your browser and PC by checking time.is. This helps prevent issues during TOTP setup.
Enabling Prompt to Set Up MFA at Login
The prompt to set up MFA is enabled by default for all users. Since MFA is a user-controlled feature, this prompt is optional and can be skipped. The account admin can hide the prompt for all users of the account.
- If the login prompt is enabled: Users will see the MFA setup page at login. They can either complete the setup or skip it. The MFA prompt only appears after a user has logged out or their session has expired.
- If the login prompt is hidden: Users will not be prompted to set up MFA at login. However, they can manually enable it at any time under Security & Authentication in the account management section (top right of the screen).
Managing MFA Settings for Your Account
Account admins can control MFA adoption through User management > Access settings. The following options are available:
-
Enabled (default): Basic MFA functionality is available without prompts. Users can enable MFA manually through their account settings.
-
Prompted: Users will see the MFA setup process when logging in. They can choose to complete the setup or skip it. The prompt only appears after a user logs out or their session expires.
-
Enforced: All users in the account must set up and use MFA. Users without MFA will be required to complete the setup on their next login.
Important: When MFA enforcement is enabled, active sessions are not terminated immediately to avoid disruptions. Users will be prompted to set up MFA only on their next login attempt.
Account admins can control which MFA methods are available to users during the MFA step. This setting is found under User Management → Access Settings → MFA Methods.
- TOTP + Passkey (default): Users can choose between TOTP and a passkey when completing the MFA step.
- Passkey only: TOTP is disabled as an MFA option. Users who already have TOTP configured may still be able to use it depending on the MFA enforcement mode. New users will only see the passkey option.
Note: Passkeys cannot be fully disabled. When a user logs in using a passkey as their primary login method (instead of email and password), the MFA step is skipped entirely.
Promotion of MFA usage
Account admins can now enforce MFA usage for all users in their account. This ensures enhanced security while maintaining operational continuity.
To encourage adoption, account admins can:
- Use the enforcement toggle to make MFA mandatory for all users
- Send email reminders to users who have not yet enabled MFA
- Monitor MFA adoption through account-level reporting
Enabling MFA for Your User Account
Users can enable MFA in three ways:
- During login: If the login prompt is enabled, follow the on-screen instructions to complete the setup.
- Through user settings: Navigate to Account Management Security & Authentication and follow the setup instructions.
- Through admin email reminders: Admins can trigger email suggesting MFA setup, and users can access the setup process through this email.
Removing MFA from Your Account
Users can disable MFA at any time from Security & Authentication in Account Management.
Important: To remove MFA, you must have access to your authentication code. If you cannot access it, refer to the Resetting MFA for Other Users section.
Once MFA is disabled, it can be re-enabled by following the setup process again.
Auditing MFA Adoption
Admins can track MFA adoption at two levels:
- Account Level: View and manage MFA settings for all users within an account. Overview of MFA adoption.
- Property Level: Track MFA adoption for specific properties.
Resetting MFA for Other Users
Only account admins can reset MFA for other users in their account.
If a user loses access to their MFA method, an administrator must reset it. The user will then be able to set up MFA again from scratch.
Too Many Failed Authentication Attempts
- If a user enters an incorrect authentication code 10 times, their account will be locked for 30 minutes.
- During this lockout period, neither account administrators nor Apaleo Support can unlock the account.
- After 30 minutes, the user can attempt authentication again.
FAQ
Do I need to enter the MFA code every-time, or can I enter it every 30 days?
Due to security reasons, if you have MFA enabled, it will be needed to be entered every time.
I have reset MFA for a user, but they did not receive an email. Can I reset again so they can set it up again?
Once you reset MFA, there is no longer the option to reset the MFA. The user can login to Apaleo and set MFA once again.
I changed my phone and need a new QR code. How can I get it?
You will need to reach out to your Account Admin, and they can reset MFA for you. Once that is performed, you can login and set MFA again.
My account got locked for 30 minutes, can I somehow enable it faster?
There is no option to unblock the account faster. You will need to wait for 30 minutes.
What is the difference between using a passkey to log in and using a passkey for MFA?
There are two distinct scenarios:
- Passkey as primary login: Instead of entering your email and password, you sign in directly with a passkey. In this case, the MFA step is skipped entirely, as the passkey itself provides strong authentication.
- Passkey as MFA: You sign in with your email and password as usual. During the MFA step, you verify your identity using a passkey instead of a TOTP code.
Using a passkey as MFA provides stronger protection than TOTP. Even if your password is leaked, an adversary cannot access your account without your physical device. Unlike TOTP codes, passkeys are phishing-resistant and cannot be intercepted or reused.