Two-Factor Authentication

Note: Two-Factor Authentication is only available to users on our Enterprise plan.

Two-Factor Authentication is a security feature available on team accounts that protects all account information beyond just using your username and password to log in. It's an optional feature that can be enabled by admins to be mandatory for all users on an account, or can be opted-in on a user by user basis for additional security if an admin has not made it mandatory.

Two-Factor Authentication in Lumen5

What is Two-Factor Authentication (2FA)?

Two-Factor Authentication (2FA) is an extra layer of security to prevent unauthorized access to your Lumen5 account. 2FA does this by requiring two successive factors – ‘something you know’ (your password) and ‘something you have access to’ (such as your mobile phone) to successfully log in to your account.

How can I make Two-Factor Authentication (2FA) required for my team?

Admins can enforce 2FA for their team, and this can easily be done in Account Settings under the Two-Factor Authentication section. By toggling the "Require 2FA for team" on, every user on the team will get an email notification that 2FA has been turned on for their account and they'll be required to set up 2FA the next time they log in.

Admins can turn off the 2FA requirement for the team by toggling off that setting in the Two-Factor Authentication section under Account Settings. This action will send an email to everyone on the team that 2FA is no longer required, and team members that have not yet set up 2FA will not be prompted to the next time they log in.

Users will always get an email notification whenever 2FA is turned on or turned off by an admin.

How do I turn Two-Factor Authentication (2FA) on and off for my account?

If an admin has made 2FA required for the team, editors cannot turn it off.

When the 2FA requirement has been disabled by the admin, team members that had 2FA enabled will continue to have 2FA security on their individual account. They can remove it in their Account Settings as long as it's disabled for the account as a whole by an admin.

**To enable 2FA on teams where 2FA is not required:**

If 2FA has not been made required on your team, you can still secure your individual account by turning on 2FA. This can be done by toggling on the Authenticator App option for Two-Factor Authentication. Similarly, to turn-off 2FA for your account, toggle the authenticator app option off.

Authenticator App FAQs

What is an authenticator app?

An authenticator app is a mobile application installed on a smartphone that generates a secure 6-8 digit passcode every 30 seconds. Your login credentials for Lumen5 and other 2FA-enabled sites are linked to your authenticator app, so when you use your username and password for a site, your authenticator app also needs to "approve" the login via a time-sensitive passcode.

Where can I get an authenticator app?

There are a variety of free authenticator apps that you can download for your smartphone. Some popular examples are Google Authenticator or Authy, both of which can be found in the Google Play and the iOS App Store.

What do I do if I've lost access to my authenticator app?

If you've lost access to your authenticator app, don't worry! There are two alternative ways you can login to Lumen5:

Using a backup code

Using a one-time secret password provided by email

To get started, click on "Try another way" under the verification code section:

Using a backup code:

When you configured 2FA, you were provided with backup codes. You can use any of those codes to log in to Lumen5.

Using email:

If you no longer have access to your backup codes, we can also send you a secure one-time password via email. Once you have received the email, you can enter the one-time password to log in to Lumen5.

Once you have successfully logged in via an alternative method, we highly encourage you to secure your account by resetting 2FA and setting up the authenticator app once again. This can be done by navigating to the Account Settings and clicking on "Reset 2FA" under the Two-Factor Authentication section.

