Theme
Secure your sign in
Everything on this page is on Account settings, and applies to your own Portal account only. It has nothing to do with the accounts your users transfer files with; those are on Users.
This page is about YOUR Portal account
Federated sign in for your transfer users (the people moving files) is a different thing, configured per site: see Sign in with your identity provider.
The rule that has no exceptions
No SFTP.cloud account is ever protected by one thing.
- If you sign in with a password, you must also have an authenticator. There is no grace period and no way to turn it off.
- If you sign in with a passkey, that is enough on its own. A passkey is already two things: the device, and the unlock that releases it.
- If you sign in with Google or Microsoft, your provider handles the second factor.
Your authenticator
Setting it up
The Portal walks you through this straight after your first sign in, and will not let you go anywhere else until it is done.
- Scan the QR code with an authenticator app, or copy the secret and enter it by hand.
- Enter the six digit code the app shows.
- Save the recovery codes.
Any TOTP app works: Google Authenticator, Microsoft Authenticator, 1Password, Bitwarden, Authy.
Replacing it
On Account settings, choose Re enroll authenticator. You will be asked to prove it is you first, with your current code, a recovery code, your password or your passkey, depending on what your account has.
Re enrolling replaces your current authenticator and issues a fresh set of recovery codes. The old codes stop working at that moment.
Recovery codes
You get ten codes, in the form ABCDE-FGHIJ-KLMNO-PQRST. They are shown once, when you enroll an authenticator, and never again. Each one works a single time, in place of a six digit code.
They are the only way back into your account if you lose your authenticator and nobody else on your team can help. Save them somewhere you can reach without your phone.
TIP
Print them, or store them in a password manager on a different device. A copy that lives only on the phone holding the authenticator protects you from nothing.
Passkeys
A passkey signs you in with your device's own unlock: fingerprint, face, PIN, or a hardware security key. It cannot be phished, and it needs no code.
To add one, on Account settings:
- Choose Add passkey.
- Give it a name you will recognize, such as
Work laptop. - Confirm with the device's unlock when the browser asks.
You can register several, one per device. To sign in with one, choose Sign in with a passkey on the sign in page. You do not type your email address first.
Removing a passkey is refused when it is the last way into your account.
Linked sign in providers
You can link a Google or a Microsoft account and sign in with it instead of a password.
Link one from Account settings, under Linked sign in providers. Unlinking is refused when that provider is the last way into your account.
Linking is always explicit and always done from inside your account. SFTP.cloud never links a provider to an existing account just because the email addresses match.
Trusted devices
When you enter a six digit code, you can tick Trust this device. That browser then stops asking for the code for the number of days the checkbox names.
Trusting a device skips the code, never the password. Somebody who steals your password still cannot get in without the device.
Account settings lists your trusted devices, when each stops being trusted, and offers Revoke all trusted devices. Revoking makes every device, including the one you are on, ask for the code again on its next sign in.
Trust is also cleared automatically when you change your password.
Changing your password
On Account settings, under Password: enter your current password, then the new one. Minimum 12 characters.
Changing it revokes every trusted device.
What is recorded
Every one of these actions is written to your account's Activity log: enrolling an authenticator, resetting one, adding or removing a passkey, changing a password. Your whole team can see the log, which is what makes an unexpected entry useful.
If somebody on your team is locked out
Support cannot reset a colleague's second factor on request alone. It needs an active support grant, which somebody signed in with the admin role must create.
So: keep at least two people with the admin role. It costs nothing and it is the difference between a five minute problem and a hard one.