Overview
Two-factor authentication (2FA) adds a second layer of security on top of your username and password. Once it is active, signing in also requires a code from an authenticator app installed on your phone or tablet, so a password on its own is not enough for someone to reach your data in DiligenceVault.
Firms typically use 2FA to:
- Protect diligence data with a second credential that stays on the user's own device
- Meet cybersecurity criteria set by the firm, its clients, or its regulators
- Apply a consistent login standard across every user in the firm through a single setting
- Give users a supported way to regain access if they lose their authenticator device
Before You Begin
- Install an authenticator app on your phone or tablet. The setup screens reference Google Authenticator.
- Keep the device with you while you complete setup, since you will need to scan a code and confirm it.
- Firm wide enforcement and 2FA resets require Super Admin or Security Admin rights.
Setting Up 2FA for Your Account
Navigation path
Click your initial in the bottom left corner, select My Settings, then go to Security > Two-Factor Authentication.
Steps
- Click your initial in the bottom left corner of the left navigation panel.
- Select My Settings.
- Select Security in the sidebar and click Two-Factor Authentication in the dropdown.
- Check the Status shown on the page. Off means 2FA is not yet active for your account.
- Click Setup two-factor authentication.
- Review the About Two-Factor Authentication screen, which explains the two sign in steps.
- Install Google Authenticator on your phone or tablet if you have not already, then tick I have installed Google Authenticator on phone or tablet.
- Click Let's get started and follow the on screen instructions to link the app and confirm your first code.
Once setup is complete, the Status on the Two-Factor Authentication page changes to On, and every future login asks for a code from your authenticator app.
Requiring 2FA for All Users
Super Admins and Security Admins can make 2FA mandatory for everyone in the firm instead of leaving it to each user.
Navigation path
Click your initial in the bottom left corner, go to Firm Settings, then Security > Two-Factor Authentication.
Steps
- Click your initial in the bottom left corner and select Firm Settings.
- Select Security in the sidebar, then click Two-Factor Authentication.
- Enable the Require 2FA for all users toggle.
What happens once the toggle is on
- Users who have already configured 2FA continue to sign in as usual.
- Users who have not configured 2FA are prompted to complete setup the next time they log in.
- Until that setup is complete, those users cannot access the platform.
Resetting 2FA for a User
If a user changes their phone, loses the device, or removes the authenticator app, a Super Admin or Security Admin can reset their 2FA so the account can be registered again.
Navigation path
From Firm Settings, go to Users & Teams and open the user record.
Steps
- Go to Firm Settings, then Users & Teams.
- Open the record of the user who needs the reset.
- Click Reset 2FA in the action bar at the top of the page.
- The user receives a confirmation email once the reset is done.
- At their next login the user is required to configure 2FA again before they can access the platform.
If You Cannot Access Your Authenticator
Users who cannot reach their authenticator app can request help directly from the sign in screen.
- On the 2FA verification screen, request your firm's Admin contact details.
- The Admin details are sent to your registered email address.
- Contact one of the listed Admins and ask them to reset your 2FA.
- Once the reset is done, you receive a confirmation email.
- Sign in again and set up 2FA with your authenticator app to regain access.
Tips and Things to Know
- Set up 2FA on a device you keep with you, since you will need it at every login.
- Codes refresh in the authenticator app, so always enter the code currently displayed.
- Keep the existing authenticator entry until your new device is registered. If you have already removed it, ask an Admin for a reset.
- Admins should tell users before switching on Require 2FA for all users, because anyone who has not set it up will be held at the setup screen until they finish.
- A reset does not disable 2FA for the user. It clears the existing registration, and the user must configure it again at the next login.
- Confirmation emails go to the registered email address on the user profile, so keep that address current.
Example Use Case
A firm is preparing for a client security review and wants every user signing in with a second factor. A Security Admin notifies the team, then opens Firm Settings > Security > Two-Factor Authentication and enables Require 2FA for all users. Users who had already set up 2FA notice no change. The rest are guided through setup at their next login and complete it in a few minutes.
A week later, an analyst replaces their phone and no longer has the authenticator entry. From the 2FA verification screen they request the Admin contact details, receive them by email, and ask the Security Admin for a reset. The Admin opens the analyst's record under Users & Teams and clicks Reset 2FA. The analyst receives a confirmation email, signs in, registers the authenticator app on the new phone, and is back in the platform without a support ticket or a password change.