Theme
Set up your second factor
A second factor means a password on its own is not enough to get into your account.
It takes two minutes, and it is the single biggest thing you can do to protect your files.
Everything here is on the Settings page of the web client.
Read this first
It covers the browser, and only the browser
An authenticator code or a passkey is asked for when you sign in with a web browser.
SFTP, FTPS and FTPES cannot ask you for a code. There is nowhere in those protocols to prompt for one. If you also connect with a desktop client or a script, your password on its own still opens your files there.
The Settings page tells you exactly which of those apply to your account, and what to ask for.
The fix for that gap is an SSH key: ask your administrator to register one for you and to remove your password. Then your key is the only way in on SFTP, and it is strong. See Use an SSH key. Short of that, use a separate app password per program instead of your account password in desktop clients: still one secret, but scoped, expiring if you wish, and revocable on its own.
Option 1: an authenticator app
An app on your phone that shows a six digit code, changing every thirty seconds. Google Authenticator, Microsoft Authenticator, 1Password, Bitwarden and Authy all work.
- On Settings, next to Authenticator app, choose Set up.
- Confirm it is you, with your password.
- Scan the QR code with the app, or enter the key by hand.
- Type the six digit code the app shows.
- Save your recovery codes.
Option 2: a passkey
A passkey lives on your device and is released by the device's own unlock: fingerprint, face, PIN, or a hardware security key.
It cannot be phished, it needs no code, and it is faster.
- On Settings, next to Passkeys, choose Add passkey.
- Confirm it is you.
- Give it a name you will recognize, such as
Work laptop. - Confirm with the device's unlock when the browser asks.
Add one per device you use. To sign in, choose Sign in with a passkey on the sign in page.
If the page says your browser does not support passkeys, use an authenticator app instead.
Your recovery codes
When you enroll an authenticator you are given a set of single use codes.
They are shown once
Each code works exactly once, in place of the six digit code. They are the way back in when your phone is lost, broken or wiped.
Store them somewhere you can reach without your phone. A copy that lives only on the phone holding the authenticator protects you from nothing.
The Settings page shows how many are unused, and warns you while you can still act:
- Running low. Generate a fresh set now, while your authenticator still works.
- None left. Generate a set immediately.
Generating a new set makes every old code stop working.
Replacing your authenticator
Got a new phone? Use Replace rather than turning the authenticator off and setting it up again.
Replacing keeps you protected the whole way through. Turning it off first leaves your account with no second factor in between, and that is the moment people get distracted and never finish.
You will be asked to confirm with your current code, a recovery code, or your passkey.
Replacing also issues a fresh set of recovery codes; the old ones stop working.
Turning it off
You can, from Settings. Turning off the authenticator also clears your trusted devices.
There is rarely a good reason to. If your authenticator is inconvenient, add a passkey instead.