Two-factor authentication (2FA)
On top of the password, HocNota can ask for a 6-digit one-time code, generated by an authenticator app on your phone (Google Authenticator, Authy, Microsoft Authenticator, 1Password…). The code changes every 30 seconds and is computed offline: no SMS and no email are involved.
Enabling 2FA on your account
From Profile → Two-factor authentication:
- Click Enable two-factor authentication.
- Scan the QR code with your authenticator app. If scanning isn't possible (a machine without a camera, a desktop app), the key is also shown in plain text just below for manual entry.
- Enter the 6-digit code shown by the app to confirm.
From your next sign-in, HocNota will ask for that code after the password.
Backup codes
Enabling 2FA displays 10 backup codes, once and only once. Each one replaces the app code, and works only once.
They exist purely to get you back in if you lose your phone: keep them somewhere other than the phone (password manager, vault, paper stored safely). At sign-in, a backup code goes into the same field as the 6-digit code.
From Profile → Two-factor authentication, the number of remaining codes is shown, and Generate new codes issues a fresh set — the previous set stops working immediately.
Disabling 2FA
Still from Profile → Two-factor authentication: enter your current password, then Disable. The password is required deliberately — an unlocked laptop must not be enough to strip the second factor off the account.
This action is unavailable if your organization requires 2FA (see below).
Requiring 2FA across the organization
From Admin → Settings → Configuration (System configuration — write permission), the Require two-factor authentication option makes the second factor mandatory for every password account in the organization.
- Live sessions are not interrupted.
- On their next sign-in, any user not yet enrolled must set 2FA up before reaching their account: the QR code is presented directly in the sign-in screen.
- While the policy is on, nobody can disable their own 2FA.
Losing your phone
If you still have a backup code, use it to sign in, then reconfigure 2FA from your profile (disable, then re-enable with the new phone).
Otherwise, an administrator (Users — write permission) resets the account's 2FA from Admin → Users: the 2FA column shows which accounts have it, and the Reset 2FA button removes the second factor. The account then signs in with its password alone until it sets 2FA up again (immediately on the next sign-in if the organization policy requires it).
An administrator can never enrol 2FA on someone's behalf: the action only ever removes, so no administrator ever holds anything that would let them sign in as a user.
Microsoft accounts (Azure AD SSO)
Accounts connected via Microsoft are not affected: their second factor is managed by Azure AD / Entra ID, in the organization's portal. The "Require two-factor authentication" policy therefore does not apply to them, and the Profile screen says so.