Skip to main content

How to enable/disable Two-Factor Authentication

Updated over a month ago

ApprovalMax supports 2FA with time-based one-time passwords. ApprovalMax Administrators can enforce users to enable it, for Australian and Xero-connected Organisations it is mandatory.


For login/password authorisation, there are three options:

  1. Verification code generated by an Authenticator application

  2. Confirmation code sent to an alternative email address

  3. Generated one-time backup code

​Suitable Authenticator applications are:

Enable 2FA

  • In My Profile under your avatar, open the Security section and click on ENABLE next to Two-factor authentication:

  • Scan the QR code or enter the shared secret generated by ApprovalMax in your Authenticator app and click on NEXT:

Please note: Complete all the steps within this pop-up window, do not click away or close it part way through. If you do click away, you’ll need to restart the process with a new QR code or key.

  • Enter the code from the Authenticator app in ApprovalMax and click on NEXT:

Please note: Make sure you're entering the most recent code from the app as these codes expire every 30 seconds.

  • Set up the alternative 2FA option, this gives ApprovalMax another way to verify your identity if you ever lose access to your Authenticator app:

    • Either generate backup codes: click on DOWNLOAD CODES (TXT FILE), or copy the codes, and save them in a safe location. You'll also need to tick the checkbox to confirm that you've saved the codes before you can move on. Remember that each code can only be used once.

Please note: When entering a backup code, type it in without spaces (eight numbers in a row).

  • Or, set up an alternative email address. After entering it, click on SEND ME THE CODE:

  • Check your inbox for a verification code sent by ApprovalMax:

  • Enter the code in the field provided and click on CONFIRM THE CODE. If you don’t receive an email, click on RESEND CODE:

  • Click on DONE to activate 2FA:

Watch this video for additional guidance on how to enable 2FA in ApprovalMax:

Please note: Having a password in place is a requirement for the 2FA setup. If you don't have one because you log in via SSO:

Disable 2FA

  • In My Profile under your avatar, open the Security section and click on DISABLE next to Two-factor authentication:

  • Confirm this with an authentication code / email confirmation code / backup code:

    • Enter the code from the Authenticator app and click on CONFIRM:


    • Or, use another authentication method:


    • Depending on which backup method you set up initially, you'll need to either enter one of the backup codes, or the email confirmation code you received. Click on PROCEED:

  • Enter the code and then click on CONFIRM:

  • Finally, click on I UNDERSTAND and two-factor authentication will be disabled:

Watch this video for additional guidance on how to disable 2FA in ApprovalMax:




Did this answer your question?