Multi-factor authentication (MFA) provides a more secure login process and adds an extra layer of security to your user accounts. Reduce the risk of internal/external fraud, identity theft, and protect your business from attacks that may compromise your data by enabling multi-factor authentication.
Using multi-factor authentication
When enabled, multi-factor authentication will:
- Require the user to input their existing password when logging in or switching users. Entering a password will trigger a password check and if the password has been compromised, the user will be notified and prompted to change their password.
- Require the user to input a six-digit authentication code generated by an authorized third-party authentication app.
- Inform users of changes to their password, email address, and MFA setup via email notifications sent to the email address associated with their user account (or the Account Owner if an email address has not been added to the account).
Setting up multi-factor authentication
To set up multi-factor authentication for a Retail POS account:
-
After logging in to Retail POS, click the user's name at the top of the sidebar > Employee settings.
-
Select Manage MFA Settings.
-
Click Enable.
-
On your phone, download an authentication app like Google Authenticator or Microsoft Authenticator and follow the steps to get set up.
-
In the authenticator app, scan the QR code to pair your mobile device and then enter the code provided by the authenticator app.
-
Ensure you’ve saved your provided recovery codes somewhere safe. Recovery codes are used to access your account if you can’t access your authentication app or code.
Ensure your codes are saved in a safe place to avoid getting locked out of your account.
-
Click I saved my codes.
After setup, authentication details appear on the main MFA page.
Logging in with multi-factor authentication
Once MFA is set up, the authentication code is found in your authenticator app.
-
Log in to Retail POS.
- Open your authenticator app on your phone.
-
Enter the 6-digit code displayed in the authenticator app. This may automatically copy on your mobile device, depending on your personal settings.
- (Optional) Select the checkbox next to Remember me on this device for 14 days to skip the MFA process for the next 14 days.
- Click Log in.
If you have lost or changed your device or can no longer access the authentication app registered to your Retail POS account, you'll need to complete an account recovery using the steps below.
Recovering accounts with multi-factor authentication
You can recover an account with multi-factor authentication enabled using the recovery codes you saved during the setup process. When a code is used, it will no longer be valid and you'll need to use another code from the list next time.
To recover an account using a recovery code:
- Log in to Retail POS.
-
In the authentication modal, click I can't access my authenticator app.
- Copy an unused recovery code from your previously saved list and enter it in the Recovery code field.
- Click Sign in.
- Follow the steps in the section below to reset multi-factor authentication on your account.
If you've lost access to your recovery codes, you'll need to contact Retail Support.
Removing multi-factor authentication
You can remove an authentication factor in the MFA settings page once you've logged in using an authentication code or with a recovery code.
To remove multi-factor authentication for a user:
- Log in to Retail POS as the user, using a saved recovery code if needed.
- Click the user's name at the top of the sidebar > Employee settings.
-
Click Manage MFA Settings.
-
Click Pause to temporarily disable MFA for this user or click the trash (Delete) icon > Remove to permanently remove it.
Once MFA has been removed, you can reconfigure it by following the steps in the Setting up multi-factor authentication section above.
What's next?
Keeping your Retail POS account secure
Learn more about keeping your account secure and steps to take if it might be compromised.
Setting up employee roles and access
Manage employee access and levels of access to your account.