Two-factor authentication adds an extra step to signing in to your Visma Recruit account. Besides your password, you enter a six-digit security code (the most common method) from an authenticator app on your mobile phone. You activate, manage and remove the feature yourself.
Note! Two-factor authentication only applies when you sign in with a username or e-mail and password. It is not used when you sign in via single sign-on (SSO), and it does not apply to candidates.
Why should I activate two-factor authentication?
Stronger protection: a stolen or guessed password is not enough to access your account.
Protects candidate data: your account gives access to personal data about applicants, and two-factor authentication reduces the risk of unauthorized access.
Quick to set up: scan a QR code and confirm with one code.
No SMS or e-mail: the codes come from the authenticator app.
Backup codes: you can still sign in if you lose your phone.
No extra cost: you do not need a separate module or user right.
Good to know before you start
You need a mobile phone with an authenticator app, for example Google Authenticator or Authy.
Your phone's clock should be set automatically. Otherwise, the codes may not be accepted.
If you can only sign in via SSO, the option is not shown. Your organisation's identity provider protects your sign-in instead.
Set up two-factor authentication
Step 1: Open "Change password"
Click your name in the top right corner.
Select Change password.
Step 2: Start the setup
Go to the Two-factor authentication section below the password fields.
Click Set up two-factor authentication.
Step 3: Generate a QR code
Read the information in the dialog.
Click Generate QR code.
Step 4: Connect the authenticator app
Open the QR code scanner in your authenticator app.
Scan the QR code on the screen.
If scanning does not work, click Enter code manually instead. A setup key is shown in groups of four characters. Type the key into the app.
Your account now appears in the app, labelled with your e-mail address or username.
Step 5: Confirm with a code
Enter the six-digit code from the app in the Authentication code field.
Click Continue.
If the code is wrong, the message “Incorrect authentication code.” is shown.
Step 6: Save your backup codes
Download the backup codes as a PDF or copy them.
Store them somewhere safe.
Click Finish set up.
Note! The backup codes are only shown once. You cannot view them again after you close the window.
The page now shows “Two-factor authentication is active for this account.” If you cancel before confirming the code, nothing is saved and two-factor authentication stays switched off.
Sign in with two-factor authentication
Sign in with your username or e-mail and password as usual.
In the authentication step, enter the current six-digit code from the app. You can also enter a backup code in the same field.
If the code is wrong, the message “Your authentication code is not correct. Please try again!” is shown.
You need to enter a new code every time you sign in.
Backup codes
Backup codes are created automatically when you set up two-factor authentication.
Each backup code can only be used once.
You can create new backup codes at any time via Create new backup codes on the Change password page. You need a current code from the app to do this.
When you have created new backup codes, use only the new set. Discard the old ones.
Remove two-factor authentication
Go to Change password in the user menu.
Click Remove two-factor authentication.
Enter the current code from the app and click Remove.
Note! You cannot use a backup code in this step.
A confirmation message is shown when two-factor authentication has been removed. You can then delete the account from your authenticator app.
Frequently asked questions
How do I change to a new phone? Sign in, remove two-factor authentication and set it up again with the new phone. If you no longer have the old phone, sign in with a backup code first.
I have lost my phone and have no backup codes. What do I do? An administrator cannot remove two-factor authentication for another user. Always keep your backup codes somewhere safe.
Why has my account been deactivated? If you enter an incorrect code more than five times in a row when signing in, the account is deactivated to protect it. Contact an administrator in your organisation to have it reactivated.
Why is the code from the app not accepted? The codes are time-based and change continuously. Check that your phone's clock is set automatically.
Can Visma Recruit remember my device? No, you need to enter a code every time you sign in.
Which apps can I use? You can use any standard authenticator app, for example Google Authenticator or Authy.
Why can I not see the two-factor authentication option? The option is not shown if you sign in via SSO, or if your account uses the older solution with printed code lists.