Coming Soon: Two Step Sign In

We are adding two step sign in over the coming weeks. After entering your password, you may be asked for a six digit code, sent by email or text message or read from an authenticator app on your phone. A password alone will no longer be enough to access an account.

If you use online banking you will already be familiar with the process. It works the same way here.

You will not be asked every time

A code is only requested after a correct password when one of the following applies:

  • New or unrecognised device. The browser has not signed in to your account before, or you chose not to remember it last time.
  • Remembered device has expired. Device trust lapses after a period. You are asked once more and the device is remembered again.
  • Wrong password entered first. If a wrong password was typed before the correct one, a code is required even on a remembered device.
  • Account policy. Your account owner can require a code on every sign in. See below.

On your own computer with Remember this device ticked, you will rarely see the code step.

How it works

Sign in with your email and password as normal. If a code is required, the sign in form is replaced by a verification card that tells you where the code has gone: Check your email, Check your phone or Open your authenticator app.

Enter the six digits, or paste the whole code into the first box, and click Verify. You are then taken into the portal as usual.

The card also offers Resend if the code has not arrived, Try another way to switch to a different method, and Back to sign in to return to the password form.

A code is valid for ten minutes. After five wrong codes the account is locked for ten minutes and you receive an email, the same as entering too many wrong passwords today.

Three ways to receive a code

Email is always on and cannot be turned off, so you can never be locked out by losing a phone. The email address on your profile must be confirmed. If it shows as unconfirmed, codes cannot be delivered, so it is worth checking now.

Text message is optional and requires a confirmed mobile number on your profile.

Authenticator app is optional and is the method we recommend. Microsoft Authenticator, Google Authenticator, Authy, 1Password and similar apps all work. The app generates a new code every thirty seconds and does not need a network signal. Setup involves scanning a QR code and entering the first code the app shows.

With more than one method enabled, you can mark one as Preferred and the sign in card will start with it.

These settings are under My Profile > Two Step Sign In.

For account owners

Where computers are shared between staff, you can require a code on every sign in for every user, regardless of remembered devices. The switch is under Settings > Account Policies and is called Always Require Two Step Sign In. It takes effect from the next sign in and is recorded in the account audit log.

Lost or replaced phone

Sign in with the email code using Try another way, then open My Profile, remove the old authenticator and set up the new phone.

Why we are adding it

Your account holds client names, contact details and appointment histories. A password on its own is a single point of failure. Passwords are reused, written down and caught by phishing. Two step sign in means a leaked password is not enough on its own.

For the public sector services we work with, this is increasingly a requirement rather than an option, and we would rather have it in place ahead of being asked.

When

Two step sign in will roll out over the coming weeks. Nothing changes until it arrives, and remembered devices will continue to sign in with a password alone. The full user guide will be published in the documentation at the same time.

If you have any questions in the meantime, please get in touch.