Caricamento

Two-factor authentication

Two-factor authentication (2FA/MFA) protects Actualog accounts when a password is guessed, reused, leaked, or phished. After the password or external sign-in succeeds, protected users must confirm access with an authenticator app or a saved recovery code.

Who must use it

MFA is required when an account has protected authority:

  • any Actualog application role;
  • any company role that grants permissions beyond public listing visibility;
  • future permission-bearing roles unless they are explicitly classified as public/no-access.

MFA is not required for:

  • an account with no application roles and no permission-bearing company roles;
  • company membership with no business-role values;
  • Public Contact Person only, because it grants only public listing visibility.

Catalog Viewer / Catalog Observer is read-only, but it can view non-public catalog and media information, so it is protected by MFA.

Available methods

Current Actualog MFA uses an authenticator app that generates time-based six-digit codes. Compatible apps include Microsoft Authenticator, Google Authenticator, 1Password, Bitwarden, and similar TOTP-compatible apps.

Recovery codes are generated after setup. Save them in a private, secure place. Each recovery code works once and is only for sign-in recovery if the authenticator app is unavailable.

A trusted browser can skip the authenticator-code prompt for up to 30 days after a successful MFA sign-in. It works across Actualog language domains for the same browser profile and account. It does not skip the password, does not grant roles, and does not bypass sensitive security checks.

Trusted-browser proof is stored by the browser as an essential protected cookie. Restarting Actualog or Windows does not revoke that proof, but a browser setting that deletes cookies on close removes it. In Microsoft Edge, check Settings → Privacy, search, and services → Clear browsing data → Clear browsing data on close. If Cookies and other site data is enabled there, Edge deletes the proof whenever the browser fully closes, including during a Windows restart.

What Actualog does not use

Actualog does not use SMS or e-mail one-time codes for this MFA foundation. Those channels are easier to compromise through SIM swap, mailbox takeover, forwarding rules, or support escalation.

Administrator limits

Application administrators and company administrators cannot set up MFA for another user. They cannot view a user's QR code, authenticator key, recovery codes, passkeys, or trusted-device secrets.

If a user needs a protected application or company role, the user must first complete MFA setup themselves. Until the pending-role workflow is added, protected role assignment is blocked when the target user is not MFA-ready.