NumNum

Setting up two-factor authentication (2FA)

With two-factor authentication (also called 2FA), you secure your account with an extra step when signing in. On top of your password, you also enter a code from an authenticator app on your phone.

Even if someone knows your password, they won’t get into your account. Since you work with invoicing and customer data in NumNum, we strongly recommend it.

💡 Tip: Two-factor authentication is recommended, not mandatory. You can dismiss the reminder and set it up later.

What you need

An authenticator app on your smartphone, for example Google Authenticator, Microsoft Authenticator, Authy or 1Password. That app generates a new six-digit code every 30 seconds.

Step 1: Go to My account

  1. Click on your name in the top right corner
  2. Select My account
  3. Scroll to the Two-factor authentication section

Step 2: Turn on two-factor authentication

  1. Click Enable two-factor authentication

  2. Enter your current password when prompted

  3. A QR code appears. Open your authenticator app and scan that code

    Can’t scan it? Click the option to enter the key manually and type it into your app.

  4. Your app now shows a six-digit code. Enter it under Verification code

  5. Click Confirm

Two-factor authentication is now active on your account.

Step 3: Store your recovery codes

Right after activating, you get a list of recovery codes. These are single-use emergency codes that let you sign in if you no longer have access to your authenticator app, for example after losing or wiping your phone.

You can copy or download them. Keep them somewhere safe outside your phone, for example in a password manager or printed in a locked drawer.

⚠️ Please note: Each recovery code works only once. If you lose both your phone and your recovery codes, you will need an admin to restore your access.

Signing in with two-factor authentication

From now on, signing in works like this:

  1. Enter your email address and password
  2. Enter the six-digit code from your authenticator app
  3. Click Verify

Don’t have your phone at hand? Click Use a recovery code and enter one of your stored emergency codes.

Viewing or regenerating recovery codes

  1. Go to My account > Two-factor authentication
  2. Click Show recovery codes or Generate new codes
  3. Confirm with your password and a valid 2FA code (or a recovery code)

If you generate new codes, the old ones expire immediately. Don’t forget to store the new list again.

Turning off two-factor authentication

  1. Go to My account > Two-factor authentication
  2. Click Disable two-factor authentication
  3. Confirm with your password and a valid 2FA code

Your account is less well protected afterwards. Only do this if there is really no alternative.

Helping a user who is locked out

Has a colleague lost both their phone and their recovery codes? An admin can then reset that user’s two-factor authentication:

  1. Go to Users and open the user
  2. In the Two-factor authentication (2FA) block, click Reset 2FA
  3. Confirm the action

That user’s authenticator and recovery codes are erased. At their next sign-in they will have to set up 2FA again.

⚠️ Please note: To reset someone else’s 2FA, you must have two-factor authentication enabled yourself. Always verify the identity of the person requesting it first, for example by phone.

Still stuck? Contact us at help@numnum.be.