With MFA on, logging in takes a password plus a 6-digit one-time code sent to the user by text message (or email) — so a stolen password alone can't reach your books. For an organization that moves money, that's cheap insurance, and GoodBooks turns it on automatically for every System Administrator.
Turning it on
MFA is set per user, by an administrator. Open Settings → Users, edit the user, and in the Multi-Factor Authentication section:
- Switch on "Require MFA at Login."
- Enter their Cell Phone (for SMS codes) — 10 digits, US/Canada.
One more step for text delivery — the user's own consent. Carrier rules require each person to opt in themselves: the user opens their Profile (their name, top of the screen), finds SMS / Text Message Preferences, confirms their mobile number, and checks the consent box. The user page shows whether they've opted in.
The person who signs an organization up can give that consent right on the signup form, so the account owner's codes can arrive by text from day one.
Until a user has both a phone on file and their opt-in, their login codes simply arrive by email instead — MFA still protects the account either way. The same happens if a text can't be delivered: the code goes to email, and the verification screen says which one to check.
Anyone added to the System Administrator group has MFA enabled automatically.
What logging in looks like
After entering their password, the user lands on Two-Factor Verification: a code has been texted to their phone (or emailed), they type the 6 digits, and they're in. On the screen:
- Remember this device — skips the code on future logins from the same browser and network. Expect to be asked again after a browser update or network change — that's the point.
- Resend Code — sends a fresh code. Give the first one a moment to arrive; a new code can be sent once every 30 seconds.
- Send to Email Instead — phone dead, left at home, no signal? One click routes the code to the account's email address.
When someone's locked out
- Can't get texts: Send to Email Instead is the built-in fallback.
- Can't get texts or email: another System Administrator edits their user page — fix the phone number, or switch "Require MFA at Login" off, let them in, and switch it back on. There are no backup codes to manage.
- New phone number: the admin updates the cell phone on the user's page, and the user re-confirms consent on their Profile.
This is one more quiet reason for the two-administrator rule — recovery always takes another admin. See Users and Permissions.
Common questions
Can I use an authenticator app (Google Authenticator, Authy)? No — codes are delivered by text or email only.
Can I require MFA for everyone at once? There's no org-wide switch; enable it per user. System Administrators — the accounts that matter most — get it automatically.
Do codes expire? Yes — codes are short-lived, so enter the code soon after it arrives; use Resend Code if it's gone stale.
Texts aren't arriving. Check the number on the user's page (10 digits, no dashes, US/Canada) and that the user completed the SMS consent on their Profile — and remember replying STOP to any GoodBooks text opts the number out until they opt back in.
Comments
0 comments
Please sign in to leave a comment.