What is TFA?
Two-Factor Authentication (TFA or 2FA) adds an extra layer of security to your account by requiring two verification steps before granting access. It reduces the risk of unauthorized access, even if your password is compromised, with the additional verification step adding an extra barrier.
At DiliTrust, we use codes sent by SMS, as this strikes a good balance between security and user-friendliness. This means that to log in to DiliTrust using TFA, a user needs:
- To know their email address or username
- To know their password
- To have access to their phone in order to receive SMS messages
Note that this option can only be enabled by an administrator.
How to enable TFA?
Navigate to your account settings by clicking on your account icon and click on “See my profile”. Then, click on “Edit”. Locate the TFA option by scrolling down to “Two-Factor Authentication” below “Password”.
Enable the TFA option by checking the box on the right.
Add the phone number you wish to use to receive the SMS verification code on. Then click on “Save”.
Next time you log into your account, you will be brought to a Two-Factor Authentication page after entering your username and password.
You will receive a different verification code by text every time you log in.
Simply type the code into the field (case-sensitive) then log in into your account.
TFA application – Set up
You can also choose, instead of the SMS verification code, to install an authentication app using your mobile device’s app store (Android/iOS).
Click on “Setup application” then enter your password to continue.
Download the app of your choice between FreeOTP or Authy.
Use your authentication application to scan the QR code displayed. You will receive a 6-digit verification code from your authentication application.
If you can't scan the QR code, click on “Can’t scan this QR code?” and manually add the code that appears to your authentication application to receive your verification code.
Enter the 6-digit code received from your authentication application.
Once verified, Board Portal will remember your mobile device and will be able to use it when logging in, to confirm that it’s you. Therefore, make sure it is your own mobile device.
Once you are done, click on “Verify and Save”.
Recovery Code – Setup
Recovery codes are pre-generated, one-time-use codes intended as a fallback method for Two-Factor Authentication.
Click on “Create my recovery codes” then enter your password. A list of codes will be automatically generated for you to use.
- Best practice: You MUST keep a copy of the generated codes somewhere outside of your account. They can be written down or screenshotted.
NB: This feature is only available to Administrators; however, they can enable it for their members.
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article