Two-factor authentication¶
Qisutu supports time-based one-time passwords and recovery codes for agents and customers.
Starting setup¶
Users start setup from their personal preferences.
QR code and authenticator code¶
Scan the QR code with a TOTP-compatible authenticator app, then enter the currently generated code to confirm setup.
Recovery codes¶
After activation, Qisutu displays the recovery codes. Store them securely and separately from the regular password.
Active two-factor authentication¶
Active two-factor authentication can be managed in personal preferences.
Signing in with a second factor¶
After successfully verifying the username and password, Qisutu requests an authenticator code or recovery code.
Administrative reset¶
Administrators can reset two-factor setup for an agent or customer contact who no longer has access to the authenticator app or recovery codes. The affected person must then set it up again in their personal preferences.