Enable and use two-factor authentication (2FA)

This article explains how to enable two-factor authentication (2FA) and how to log in to FreeAgent using 2FA. It also explains how to disable 2FA.

2FA is an optional security feature in FreeAgent that keeps your account secure if your log in credentials ever fall into the wrong hands. Enabling it can help prevent your FreeAgent account from unauthorised access, fraud and abuse.

Once enabled, 2FA works in conjunction with an authenticator app on your iOS or Android device to prompt you to enter a randomly generated verification code - in addition to your regular log in credentials - every time you want to access your FreeAgent account.

Alternatively, you can set up a new email check which will send a verification code to your email address when you log in to your FreeAgent using a new device that isn't a known device, or after clearing cookies. This option is less secure than 2FA however, so we do recommend you also enable 2FA if you choose to enable a new login check.

Please note:

  • To enable 2FA, you'll need to download an authenticator app on your iOS or Android device that'll allow you to generate the verification codes you'll need to log in to your FreeAgent account. 
     
  • The code will always be generated on an authenticator app and will never be sent via SMS.

If you're unable to log in to your FreeAgent account, please see our troubleshooting steps for login problems.

Enable 2FA

Select 'Settings' from the drop-down menu in the top-right corner and then select 'Sign-in and Security'.

'Sign-in and Security' highlighted under Account Security.

Select the ‘Set up’ button next to the ‘Authenticator app’ option.

'Set up' button highlighted next to 'Authenticator app'.

Setting up an authenticator app involves four steps.

  1. Downloading an authenticator app
  2. Scanning the QR code
  3. Entering the code
  4. Saving the recovery codes

1. Download an authenticator app

If you haven't already done so, download an authenticator app on your mobile device and select 'Continue'.

If your authenticator app supports cloud backup, we recommend enabling it. In the event that you get a new device, you’ll then be able to transfer your authenticator app data to it using this feature. This will help you to avoid being locked out of FreeAgent and having to set up 2FA again.

'Continue' button highlighted on Step 1 page.

2. Scan the QR code 

Use the authenticator app on your device to scan the QR code that appears in the pop-up box and then select 'Continue'.

Step 2 showing QR code and 'Continue' button.

3. Enter the code 

The app will then generate a 6-digit code. Enter the code in the 'Verification code' field and select ‘Verify code and continue’.  

Field for six digit code and 'Verify code and continue' button highlighted on Step 3 page.

4. Save the recovery codes 

Next, you'll be shown your recovery codes which you should keep saved in case you need them in future. 

Please note that these codes should not be used each time you log in to your account as they are intended to be used for emergencies such as loss of a device or email access.

Once 2FA is set up, recovery codes should only be used to get you back into your FreeAgent account if you get a new device, lose access to your device, or delete your authenticator app. Please make sure you print them or save them somewhere safe.

Step 4 page showing list of backup codes and options to 'Copy codes' and 'Print codes'.

Once you've saved the recovery codes, select 'Confirm and finish' to complete the process.

The 'Authenticator app' option will then show as enabled.

Authenticator app showing as 'Enabled'.

Logging in to FreeAgent using 2FA

Once you have successfully set up 2FA, you'll need to use your authenticator app to generate a code each time you log in to FreeAgent, even if that device is known.

After entering your usual login credentials, enter your verification code and select 'Log in'.

Field to enter verification code and 'Log in' button.

What to do if you're locked out 

If you're unable to access your authenticator app, your recovery codes provide you with another way to log in to your FreeAgent account. Select ‘I want to use a recovery code'.

'I want to use a recovery code' highlighted on 2 Factor Authentication window.

Find your recovery codes from their secure location, type one of them into the box and select 'Log in'.

Each of your 10 recovery codes can only be used once. If you need to, you can generate a fresh set of recovery codes. Please be aware that when you do this, all your previous recovery codes - including those you’ve not yet used - will become invalid, so remember to print or save your new codes to your secure location.

Recovery code window with field to enter code and 'Log in' button.

If you don't have access to your recovery codes, please contact our support team by selecting the blue Help button at the bottom of the screen and they'll take you through an identity verification procedure before allowing you back into your account.

Generating new recovery codes 

In the 'Account recovery' section of the 'Sign-in and Security' area, select 'View codes'.

'View codes' button highlighted next to 2FA recovery codes.

Select ‘Generate new codes’.

'Generate new codes' button highlighted on Recovery codes window.

Remember to print or save your new codes to a secure location.

Disable 2FA

To disable 2FA, select ‘Disable’ to the right of ‘Authenticator app'.

'Disable' button highlighted next to Authenticator app.

A pop up window will appear asking if you are sure that you want to disable this authentication. Select ‘Disable’ to complete the process.

'Are you sure you want to disable this authentication?' pop up window.

You'll then be able to log in to your dashboard with only your email address and password.

Managing 2FA when changing devices

If you're changing mobile devices, you'll need to disable the current 2FA set up using the old device. Then, enable 2FA using the new device.

If you're using a switching service, ensure the authenticator app works on the new device before getting rid of the old device.

Did you find this article useful?