> For the complete documentation index, see [llms.txt](https://en.help.firstline.cc/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://en.help.firstline.cc/feature/admin/employee/two-factor-authentication.md).

# Two-Factor Authentication (2FA)

Two-factor authentication (2FA) adds an authenticator verification step beyond the account password, helping improve the login security of FIRST LINE accounts. This article explains how to enable it, log in, save recovery codes, and handle the loss of a device.

{% hint style="info" %}
**2026 Q3 New Features**

FIRST LINE added the “Two-Factor Authentication (2FA)” feature in Q3 2026. Once enabled, when logging in to FIRST LINE with your account and password, in addition to your password, you must also enter a verification code generated by an authenticator app, adding a second layer of login protection to your account.
{% endhint %}

## What is two-factor authentication

Two-Factor Authentication (2FA) adds an extra identity verification method in addition to your account password.

FIRST LINE's two-factor authentication uses a one-time verification code generated by an authenticator app. After setup is complete, each time you log in to FIRST LINE with your account and password, in addition to entering your existing password, you also need to enter the **6-digit verification code**.

You can use an authenticator app that supports TOTP codes, such as Google Authenticator, Microsoft Authenticator, 1Password, and others.

{% hint style="info" %}
If a company uses Microsoft SSO to log in, the login verification method will follow the company's identity service and Microsoft Entra ID security policies, and will not use the two-factor authentication flow for logging in with a FIRST LINE account and password.
{% endhint %}

<figure><img src="https://3300265106-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MNRu7dk70ei7JV9HlW9%2Fuploads%2FyyRJ1QW9MesOi00dgw29%2FScreenshot%202026-08-20%20at%2011-12-34.png?alt=media&amp;token=98e30b6d-09ad-4a72-b092-fd018b2a24b4" alt=""><figcaption></figcaption></figure>

## Enable two-factor authentication

You can enable your own two-factor authentication from Personal Settings.

Go to:

**Top-right navigation bar → profile picture → Personal Settings → Privacy & Security → Two-Factor Authentication**

### 1. Start authenticator setup

After entering “Two-Factor Authentication,” choose to enable the feature. The system will display the authenticator setup screen, including:

* QR code
* Setup key
* 6-digit verification code input field

### 2. Add FIRST LINE to the authenticator app

It is recommended to directly use the authenticator app to scan the **QR code**.

If you cannot scan the QR code right now, you can also copy the “**Setup key**” on the screen and manually add the account in the authenticator app.

{% hint style="warning" %}
**Please keep the setup key safe and do not send it to others.**

Anyone who obtains the setup key may be able to create the same authenticator on another device, so treat it as account security information and keep it safe.
{% endhint %}

### 3. Enter the 6-digit verification code

After scanning or adding manually is complete, the authenticator app will begin displaying a one-time 6-digit verification code.

Enter the currently displayed **6-digit verification code**into FIRST LINE, and click "Confirm."

Once verification succeeds, two-factor authentication will be officially enabled.

{% hint style="info" %}
Completing only the QR code scan or adding the setup key does not mean two-factor authentication has been enabled. You still need to enter the 6-digit verification code currently displayed in the authenticator and complete confirmation.
{% endhint %}

## Save recovery codes

After completing the two-factor authentication setup, FIRST LINE will provide a set of**recovery codes**.

Recovery codes can be used as a backup verification method for logging in when you temporarily cannot use your original authenticator app.

You can directly copy the recovery codes, or download and store them in a safe place.

{% hint style="warning" %}
**Be sure to save the recovery codes before leaving the setup screen.**

Recovery codes are only displayed in plain text at the moment they are generated; afterward, you cannot view the original contents again. If they are lost, you can only generate a new set of recovery codes.
{% endhint %}

Each recovery code can only be used successfully once. After it is used, that recovery code becomes invalid.

<figure><img src="https://3300265106-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MNRu7dk70ei7JV9HlW9%2Fuploads%2FeKqhkXRTnpWGIf03Qe1S%2FScreenshot%202026-08-20%20at%2011-08-33.png?alt=media&amp;token=0bf62ea6-b9c7-4079-9f6d-5c4660b157a8" alt=""><figcaption></figcaption></figure>

## How to log in after enabling

Once your account has two-factor authentication enabled, logging in with your FIRST LINE account and password will add one more verification step to the login process.

1. Enter your FIRST LINE account and password.
2. The system will require you to enter the two-factor authentication code.
3. Open the authenticator app you previously linked.
4. Enter the currently displayed 6-digit verification code.
5. After verification succeeds, you can enter FIRST LINE.

The verification codes generated by the authenticator are updated periodically, so please use the app's**currently displayed verification code**as the reference.

### When the authenticator cannot be used

If you cannot obtain the 6-digit verification code from the authenticator app at the moment, you can use a previously saved and unused**recovery codes**to complete two-factor authentication.

Once a recovery code is used successfully, it becomes invalid immediately. The next time you need to use a backup method, please use another unused recovery code.

## Manage your own two-factor authentication

After enabling, you can return to:

**Top-right navigation bar → profile picture → Personal Settings → Privacy & Security → Two-Factor Authentication**

View the current two-factor authentication status.

The screen will show whether it is currently enabled and the number of unused recovery codes. Depending on the current settings, you can also do the following:

### Regenerate recovery codes

If the original recovery codes are lost, leaked, or the remaining number is insufficient, you can regenerate a new set of recovery codes.

Before regenerating, FIRST LINE will ask you to enter your current account password again for confirmation.

{% hint style="warning" %}
After regenerating the recovery codes,**all original recovery codes will become invalid immediately**. Please save the newly generated recovery codes again.
{% endhint %}

### Disable two-factor authentication

If the company does not require two-factor authentication, you can disable this feature from Personal Settings.

Before disabling, the system will ask you to re-enter your current account password to confirm your identity.

After disabling, logging in with your account and password will no longer require FIRST LINE's 6-digit two-factor authentication code.

## What to do if you lose or replace your phone

If the phone originally linked to the authenticator is lost, damaged, or unusable, you can take the following actions depending on the situation:

### There are still usable recovery codes

Use an unused recovery code to complete login, then go to Personal Settings to manage two-factor authentication.

You can regenerate the recovery codes as needed, or, if disabling is allowed, disable two-factor authentication first and then complete setup again with a new authenticator.

### Cannot use the authenticator and have no recovery codes

Please contact your company's FIRST LINE administrator for help resetting two-factor authentication.

The administrator can reset the account's two-factor authentication from the employee's security settings. After the reset, the original authenticator setup and recovery codes can no longer be used, and you will need to complete the two-factor authentication setup again.

{% hint style="warning" %}
To prevent the account from being impersonated by others, before the administrator resets two-factor authentication, it is recommended to verify the applicant's identity according to the company's internal process.
{% endhint %}

<figure><img src="https://3300265106-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MNRu7dk70ei7JV9HlW9%2Fuploads%2FLjxR9hdWTiPHXamwCoUa%2FScreenshot%202026-08-20%20at%2011-16-47.png?alt=media&amp;token=dad57c93-5e3a-4b71-9b54-44494fe36d06" alt=""><figcaption></figcaption></figure>

## Company-enforced two-factor authentication

Company administrators can require members to use two-factor authentication and set an activation deadline according to company policy.

If the company has enabled mandatory two-factor authentication and your account has not yet completed setup, when the setup deadline expires and you log in to FIRST LINE, the system will first guide you to complete the two-factor authentication setup.

You need to complete:

1. Use the authenticator app to scan the QR code, or manually enter the setup key.
2. Enter the 6-digit verification code currently displayed in the authenticator.
3. Save the system-generated recovery codes.

After completing this, you can continue into FIRST LINE and use the original features.

{% hint style="info" %}
Under the scenario where the company enforces two-factor authentication, individuals cannot skip the required setup process on their own. If you cannot complete verification due to device loss or other reasons, please contact the company administrator for assistance.
{% endhint %}

## Usage recommendations

To reduce the risk of being unable to log in or of verification information being leaked, it is recommended to:

* Store the recovery codes in a safe place different from the phone used for the authenticator.
* Do not provide the QR code, setup key, verification code, or recovery codes to other people.
* Before changing phones, confirm that the new authenticator setup and recovery method are ready.
* If you suspect the setup key or recovery codes have been leaked, immediately reset two-factor authentication or regenerate the recovery codes.
* Company administrators can, in conjunction with the organization's account security policy, decide whether to require all members to use two-factor authentication.
