Two-Factor Authentication
Enable Two-Factor Authentication in user accounts.
Summary
To enhance security, Corefinity Control Panel supports Two-Factor Authentication (2FA) through Google Authenticator or SMS. Two-factor authentication protects against phishing, social engineering, and password brute force attacks and secures your logins from attackers exploiting weak or stolen credentials.
While 2FA is recommended, it is not required for Control Panel users by default. However, the Company Owner or anyone with the Force 2FA permission can enforce it. In that case, users will be required to activate at least one 2FA method upon signing in for the first time.
Setting Up Google 2FA
- Log In to Control Panel:
- Access your account at manage.corefinity.com.
- Go to Profile Settings:
- Click on your user avatar at the top-right.
- Select Profile from the dropdown.

- Navigate to Two-Factor Authentication:
- On the left menu, click Two-Factor Authentication.
- Next to Google 2FA, click Setup.

- Save Your Recovery Code:
- Youβll be shown a Recovery Code. Save this in a secure place.
You will need this recovery code to regain access if you lose your authenticator.
- Scan the QR Code or Use the Key:
- Use an authenticator app (e.g. Google Authenticator) to scan the QR code or enter the provided key manually.
- Activate 2FA:
- Enter the 6-digit OTP from your app in the Enter OTP Here box.
- Click Activate 2FA.

After activating, you will be required to enter an OTP from your authenticator each time you log in.
Setting Up SMS 2FA
- Log In to Control Panel
- Access your account at manage.corefinity.com.
- Go to Profile Settings:
- Click on your user avatar at the top-right.
- Select Profile from the dropdown.

- Navigate to Two-Factor Authentication:
- On the left menu, click Two-Factor Authentication.
- Navigate to the SMS 2FA section.

- Verify Your Mobile Number:
- If your mobile number isnβt verified yet:
- Click Verify your Mobile Number.
- You will be redirected to the profile tab.
- Enter your number and country code and click Update.

- Enable SMS 2FA:
- You will receive a text message with a code, enter that code in the field and click Verify.
- Then, in the SMS 2FA under Two-Factor Authentication, click the Enable button.


SMS-based 2FA requires a valid verified mobile number.
You can enable both 2FA methods at the same time.
Disabling 2FA
- Log In to Control Panel:
- Access your account at manage.corefinity.com.
- Go to Profile Settings:
- Click on your user avatar at the top-right.
- Select Profile from the dropdown.
- On the left menu, click Two-Factor Authentication.
- You will see the Disable button to next to any method enabled.

Recovery
If you lose access to your 2FA method:
- Use your Recovery Code provided during setup.
- Recovery codes are used to access your account in the event you cannot receive two-factor authentication codes.
- Download, print, or copy your codes before continuing the two-factor authentication setup.
- If recovery is not possible, and you cannot contact support via the Tickets section of the control panel, email support@corefinity.com for assistance.