TimeZest now supports two-factor authentication (2FA) using common applications such as Authy, Google Authenticator and Microsoft Authenticator. Two-Factor Authentication works by ensuring that you have two factors to identify yourself when signing into TimeZest - your password (as is used currently), and your phone (when 2FA is enabled). This significantly increases the security of your account, as it prevents someone logging in if your password is compromised or stolen.
As part of our commitment to security, 2FA is available to all users of TimeZest, including subscribers on free plans.
Important: Under no circumstances will TimeZest support turn off 2FA for an account where it has been configured, as this is a vector of social engineering attacks that can be used to bypass 2FA, and thus render it useless. Administrators can disable 2FA for other users if required (e.g. after losing a device).
Setting up 2FA for individual users
Each TimeZest user can setup 2FA for themselves in their My Profile page.
To enable 2FA for your own account, click the Enable 2FA button. You'll then be asked to add TimeZest to your authenticator app using a QR code:
After entering the code, click Verify & Continue. You will then be shown backup codes which you can use to bypass 2FA if you lose your authentication device. It is critical that you store these in a secure place.
Click Finish & Enable 2FA, and you will be prompted to use your authenticator app next time you log in.
Enforcing 2FA for all users
TimeZest can also be configured to require all users to set up 2FA. This can be configured in the Security & Permissions page:
Click Enable 2FA to require all users to configure 2FA. They will be prompted at their next login but there is a grace period of 7 days during which it can be skipped. After the grace period expires, users will be required to configure 2FA before being allowed to login to TimeZest.
Disabling 2FA for Individual users
In the case where a user loses their 2FA device, it's possible for another user with permissions to disable 2FA for that user for their next login attempt only. This can be done by going to that user's profile > Security page and clicking Disable 2FA for Next Login button.





