> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://help.cxplanner.com/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# Enable two-factor authentication (2FA) for your account

## Overview: enable two-factor authentication

Two-factor authentication in **Account settings** requires a one-time code from an authenticator app in addition to your password when you log in, which is used to reduce unauthorized access to your CxPlanner account.

If your company uses SSO, password and 2FA settings may be managed by your company identity provider instead. For hardware keys, see [Link a YubiKey to your CxPlanner profile](https://help.cxplanner.com/en-us/article/link-a-yubikey-to-your-cxplanner-profile-my7uel/).

* Your role can be any role with a CxPlanner password login.
* You can find the menu at Profile icon - **Account settings** - **2FA**.
* This changes your login flow so a one-time code is required after your password.

|| Any user with password login can enable 2FA. SSO accounts may not manage 2FA here.

## How to enable 2FA

1. Click your **profile icon** in the top right corner.
2. Select **Account settings**.
3. Scroll down to the **2FA** section.
4. Scan the QR code with your authenticator app, for example Google Authenticator or Microsoft Authenticator.
5. Confirm setup with the code from the app if prompted.

![Screenshot: 2FA QR code section in Account settings](https://storage.crisp.chat/users/helpdesk/website/ea2cfd7bb6130800/image_1s45w1.png)

## Results: login after enabling 2FA

* Every login asks for a one-time code from your authenticator app
* The code refreshes about every 30 seconds
* Losing access to the authenticator app can lock you out until an admin resets 2FA

## Troubleshooting: two-factor authentication

| Problem | Cause | Solution |
|---|---|---|
| Cannot log in with 2FA | Code expired or typed incorrectly | Open the authenticator app, wait for a fresh code, and try again |
| Lost access to the 2FA device | No backup authenticator available | Ask a **Company Admin** to reset your login method, and include your email and company name in the request |
| QR code will not scan | App cannot read the screen QR | Enter the setup key manually in the authenticator app, then confirm with a generated code |