Theme
Administrators
System, then Administrators.
These accounts are local to this Connector. They work offline, they are separate from your SFTP.cloud Portal team, and Syncplify has no access to them.
Create at least two
There is no remote reset for these accounts. If the only administrator loses their password and their recovery codes, there is no supported way back in.
A second administrator is the whole answer, and it costs nothing.
Creating one
Choose New administrator and set a username and a password.
They enroll their own authenticator at their first sign in. You never see or set their second factor.
The TOTP grace (days) setting on Settings decides how long they may sign in before enrollment becomes mandatory.
Your own second factor
Under Your authenticator app:
| Action | Notes |
|---|---|
| Enroll an authenticator | First time setup |
| Replace the authenticator | Needs the current one first: a code, or one unused recovery code |
| New recovery codes | Replaces every earlier code |
Recovery codes are shown once. Store them somewhere safe, away from this machine.
The page tells you how many are left, and warns you while you still hold a working authenticator. Generate a fresh set then, not after.
Trusted devices
Devices you told this Connector to trust skip the six digit code for the configured window.
Revoke all trusted devices makes every one of them ask again at its next sign in, including the one you are on.
Set the trust window to 0 on Settings to disable the feature entirely.
Managing other administrators
| Action | Effect |
|---|---|
| Change password | Signs that administrator out everywhere and forgets their trusted devices |
| Disable or Enable | Suspends or restores an account |
| Reset two factor | The lost phone path. They sign in with their password alone until they enroll a new authenticator |
| Delete | Removes the account |
At least one active administrator always remains. The last one cannot be deleted or disabled.
Resetting two factor is a real reduction
Between the reset and the new enrollment, that account is protected by a password alone. Do it when you know who is asking, and confirm the enrollment happened.
Sign in lockout
Too many failed attempts locks the sign in for a few minutes. Wait it out. There is no unlock button, deliberately.
What these accounts control
Everything on this Connector: virtual file systems, permissions, encryption keys, scripts, settings, the enrollment.
They do not control anything in the Portal, and they cannot see or change your users' credentials, which live on your site.