Multi-factor authentication (MFA) adds a second check to signing in: after your password, you confirm a code or a device that only you hold. You set up and manage these methods on your security page, and you generate recovery codes as a fallback for the times you lose your usual device.
Supported methods
Your security page lists the second-factor methods your organisation allows. Each option shows a short note on how it works and a "Configure" button to turn it on:
- Authenticator app — use an app such as Google Authenticator or Authy to generate a rolling code.
- SMS verification — receive codes by text message.
- Email verification — receive codes by email.
- Passkey / security key — use a passkey or a hardware security key.
Which of these appear depends on the verification methods your organisation enables. An administrator sets that on the organisation's security settings, which also decide whether MFA is optional or required for everyone signing in.
An authenticator app or a passkey stays with a device you carry, so it keeps working even when you have no mobile signal. Text and email codes are convenient, but they depend on you being able to reach that number or inbox.
Enrolment
You reach your security page from the user menu in the header — the round avatar at the top labelled "User menu" — which also holds the rest of your profile and security settings.
To turn on a method:
- Open the user menu in the header and go to your security settings.
- Find the method you want and select "Configure" next to it.
- Follow the prompts to link it:
- For an authenticator app, add the account to your app and enter the one-time code it shows.
- For text or email verification, confirm the number or address, then enter the code Pyron sends you.
- For a passkey or security key, register the device when your browser asks.
- Pyron confirms the method once it verifies your code or device. It then counts as set up, and you can turn it off again from the same place.
If your organisation requires MFA, you are asked to set up at least one method before you can continue. Setting up more than one gives you a way in if a single method becomes unavailable. From then on, Pyron asks for your second factor each time you sign in.
Backup codes
Recovery codes are your backup way into Pyron when you cannot use your usual second factor — for example, if you lose the phone that runs your authenticator app. The recovery codes section of your security page explains this and gives you a button to create a set.
To make a set, select "Generate recovery codes". Store the codes somewhere safe and private, kept apart from the device that runs your other methods, since they let anyone who holds them past the second step. Each code works once.
If you use up your recovery codes and lose your second factor as well, you can be locked out. An administrator can reset your MFA so you can set it up from scratch and sign in again.