Multi-factor authentication (MFA) adds a second verification step at sign-in. Users enable MFA on their own account from the Profile page accessed via their avatar in the top right.
MFA is available to all users on all subscription tiers
Each user enables MFA on their own account
Open the Profile page from your avatar dropdown (top right)
If your organisation uses SSO, MFA is typically enforced by your identity provider rather than ReFresh
Save the recovery codes provided when you enable MFA
Why use MFA
MFA reduces the risk that a stolen password alone gives an attacker access to your account. It pairs your password with a second verification step, typically a one-time code from an authenticator app or sent to a registered device.
For users with admin permissions in ReFresh, MFA is strongly recommended.
Enabling MFA on your account
Click your avatar / name in the top right.
Click Profile.
Find the security or MFA section.
Choose your second factor (typically an authenticator app such as Google Authenticator, Microsoft Authenticator, or 1Password).
Scan the QR code or enter the secret into your authenticator app.
Enter the code your authenticator generates to confirm.
Save and store any recovery codes provided in a safe place.
Tenant-level MFA enforcement
If your organisation uses SSO through Google, Microsoft, Okta, or another identity provider, MFA is typically configured and enforced in that identity provider. ReFresh inherits whatever sign-in policy your IdP applies.
If you do not use SSO and want all users in your organisation to use MFA, contact your ReFresh account contact.
Recovering access if you lose your MFA device
If you lose access to your authenticator app or device:
Use a saved recovery code if you have one
Otherwise, contact an Organization Admin in your organisation to reset your MFA
If no other Organization Admin is available, contact ReFresh support
Related articles
Logging in and navigating ReFresh (1.2)
Setting up SSO (2.6)
Login and SSO issues (9.1)