Skip to main content

Multi-factor authentication

Multi-factor authentication (MFA) adds a second verification step at sign-in, so a stolen password alone is not enough to reach your account. Each person enables MFA on their own account using an authenticator app.

Written by Taylor Laing
  • MFA is available to all users on every subscription tier.

  • Each user enables MFA on their own account.

  • ReFresh uses time-based one-time codes (TOTP) from an authenticator app, plus one-time recovery codes.

  • If your organisation uses SSO, MFA is typically enforced by your identity provider rather than by ReFresh.

  • Save the recovery codes shown when you enable MFA; they are your backup if you lose your device.

Why use MFA

MFA pairs your password with a second factor: a one-time code generated by an authenticator app on your phone. Even if someone learns your password, they cannot sign in without that rotating code.

If you have admin permissions in ReFresh, MFA is strongly recommended.

Enabling MFA on your account

Workers manage MFA from My ReFresh → Settings → Security (/portal/settings/security). Admins manage it from their Profile, opened from the avatar dropdown in the top right.

  1. Open your Security settings (worker portal) or your Profile (admin workspace).

  2. Find the multi-factor authentication section and start setup.

  3. Scan the QR code with an authenticator app such as Google Authenticator, Microsoft Authenticator, or 1Password (or enter the secret key manually).

  4. Enter the six-digit code your authenticator generates to confirm.

  5. Save your recovery codes somewhere safe; a password manager is ideal. Each code can be used once if you cannot reach your authenticator.

When your organisation uses SSO

If your organisation signs in through Microsoft Entra ID, Okta, Google Workspace, JumpCloud, or another identity provider, MFA is configured and enforced in that identity provider. ReFresh inherits whatever sign-in policy your IdP applies, so you generally will not enable MFA separately in ReFresh.

If you do not use SSO and want everyone in your organisation to use MFA, contact your ReFresh account contact to discuss enforcement options.

If you lose your MFA device

If you can no longer reach your authenticator app:

  • Use one of the recovery codes you saved when you enabled MFA.

  • If you have no recovery codes left, ask an Admin or Organization Admin in your organisation to reset your MFA.

  • If no admin is available, contact ReFresh support.

Did this answer your question?