Setting up two-factor authentication

Protect your account with two-factor authentication (2FA) using an authenticator app for an extra layer of security.

Why enable two-factor authentication?

Two-factor authentication (2FA) adds an extra layer of protection to your account. Even if someone obtains your password, they cannot access your account without the verification code from your authenticator app.

With 2FA enabled, signing in requires both your password and a time-based code generated by your authenticator app. This significantly reduces the risk of unauthorised access.

What you need

Before setting up 2FA, install an authenticator app on your phone. Common options include:

  • Google Authenticator
  • Microsoft Authenticator
  • Authy
  • 1Password

Enabling two-factor authentication

  • Click your name at the bottom of the navigation bar.
  • Click Manage account to open the profile management screen.
  • Select Security from the left menu.
  • Under Two-step verification, click + Add two-step verification.
  • A QR code will be displayed. Open your authenticator app and scan the QR code.
  • Enter the verification code shown in your authenticator app.
  • Click Verify to complete setup.

Your account is now protected with two-factor authentication. Each time you sign in, you will be prompted to enter a code from your authenticator app after entering your password.


FAQ

Can I use SMS for two-factor authentication?

No. Curia supports authenticator app codes only. SMS-based verification is not available as authenticator apps provide stronger security.

Which authenticator apps are supported?

Any app that supports time-based one-time passwords (TOTP) will work, including Google Authenticator, Microsoft Authenticator, Authy, and 1Password.

What if I lose access to my authenticator app?

Contact your account administrator or Curia support to have two-factor authentication reset on your account.

Can I disable two-factor authentication after enabling it?

Yes. Go to Security in your account settings and remove two-step verification. However, keeping 2FA enabled is strongly recommended.


Was this article helpful?