Skip to main content

Set up and use two-factor authentication (2FA)

How Two-Factor-Authentification works at Candis

Written by René Wasmuß

Two-factor authentication, or 2FA, adds an additional security check after you enter your email address and password. This article explains which authentication methods Candis supports, how to set up an authenticator app, and how to use an alternative method when your preferred method is unavailable.

When Candis requires two-factor authentication

Candis requires all users who sign in with an email address and password to complete two-factor authentication. Your assigned role does not affect this requirement.

To complete two-factor authentication, you need access to at least one of the following options:

  • The Candis app on your smartphone

  • An authenticator app on your smartphone

  • The inbox of the email address linked to your Candis account

  • A verified mobile number, if Candis offers SMS authentication for your account

Note: Candis does not ask for a separate Candis two-factor authentication when you sign in through single sign-on. Your company’s identity provider manages the authentication process.


Available authentication methods

Candis offers three primary authentication methods:

Method

How the method works

Recommendation

Push notification in the Candis app

Candis sends a sign-in request to the Candis app. You check the sign-in details and select Confirm or Reject.

Recommended method

Authenticator app

An authenticator app generates a six-digit code. You enter the current code when signing in.

Recommended alternative

Email

Candis sends a six-digit code to your email address. You enter the code on the sign-in page.

Alternative method

Depending on your account, Candis may also show SMS as an alternative authentication method. You need a verified mobile number from a supported country to receive a code by SMS.

Security: Use the Candis app or an authenticator app whenever possible. Email does not provide a fully separate second factor if you access Candis and your email inbox on the same device.


Use the Candis app for two-factor authentication

The Candis app provides the recommended authentication method for signing in through a web browser.

Candis automatically activates push notifications as an authentication method after you sign in to the Candis app once. You do not need to enable an additional setting in your Candis profile.

When you sign in through a web browser, Candis sends a request to your smartphone. The Candis app shows information about the sign-in attempt, including the account, device, and browser.

Check the displayed information and select:

  • Confirm if you started the sign-in attempt.

  • Reject if you did not start the sign-in attempt.

Tip: Enable push notifications for the Candis app in your smartphone settings. Without push notifications, you may not receive the sign-in request immediately.

Note: The article Two-factor authentication with the Candis app contains the complete step-by-step instructions for confirming a sign-in through a push notification.


Prepare an authenticator app

An authenticator app generates time-limited authentication codes on your smartphone. You can use Google Authenticator, Microsoft Authenticator, or another compatible authenticator app. Install a compatible authenticator app from your device’s app store before you connect the authenticator app to your Candis account.


Set up an authenticator app in Candis

  1. Sign in to Candis.

  2. Complete the current two-factor authentication if Candis asks you to verify the sign-in.

  3. Open your Profile settings.

  4. Find Authenticator app under Account security.

  5. Select Add.

  6. Open the authenticator app on your smartphone.

  7. Select the option for scanning a QR code. The exact name of this option depends on the authenticator app.

  8. Scan the QR code shown in Candis.

  9. Enter the six-digit code from the authenticator app in Candis.

  10. Confirm the setup.

  11. Close the setup window after Candis confirms that the authenticator app has been connected.

Note: Authenticator apps usually generate a new code every 30 seconds. Always enter the code currently shown in the authenticator app. If a code expires while you enter it, use the newly generated code.

Security: Do not share the QR code or any six-digit authentication code with another person. Another person could use the QR code to connect an authenticator app to your account.


Sign in with an authenticator app

  1. Open my.candis.io in your web browser.

  2. Enter your email address and password.

  3. Open the authenticator app on your smartphone.

  4. Find the entry for Candis.

  5. Enter the current six-digit code in Candis.

  6. Complete the sign-in.

If Candis does not accept the code:

  • Use the newest code from the authenticator app.

  • Wait for a new code if the current code is about to expire.

  • Check that your smartphone sets its date and time automatically.

  • Check that you selected the correct Candis entry in the authenticator app.


Use two-factor authentication by email

When you use email authentication, Candis sends a six-digit code to the email address linked to your account.

  1. Open my.candis.io in your web browser.

  2. Enter your email address and password.

  3. Select Try another way if Candis initially asks you to use a different authentication method.

  4. Select Email.

  5. Open the inbox of the email address linked to your Candis account.

  6. Find the email containing the six-digit code.

  7. Enter the six-digit code on the Candis sign-in page.

  8. Complete the sign-in.

The email code:

  • Works for one sign-in only

  • Remains valid for a maximum of 15 minutes

Tip: Check your spam folder if you do not receive the email. If you requested more than one code, always use the code from the newest email.

Note: Request a new code if the existing code has expired. You cannot reuse an expired code.


Use two-factor authentication by SMS

Candis only shows SMS authentication if your account contains a verified mobile number and Candis supports the country associated with that mobile number.

  1. Open my.candis.io in your web browser.

  2. Enter your email address and password.

  3. Select Try another way.

  4. Select SMS if Candis shows the method for your account.

  5. Open the SMS on your smartphone.

  6. Enter the code from the SMS on the Candis sign-in page.

  7. Complete the sign-in.

Note: Use another authentication method if Candis cannot send an SMS to your mobile number. The article Supported countries for SMS verification lists the countries available for SMS authentication.


Use an alternative authentication method

Use an alternative method if you cannot access your preferred authentication method:

  1. Start the sign-in with your email address and password.

  2. Select Try another way on the authentication page.

  3. Choose one of the authentication methods shown for your account.

  4. Complete the authentication with the selected method.

Candis only shows authentication methods available for your account. Depending on your account configuration, you may see email or SMS as an alternative.

Tip: Use email or SMS as a temporary alternative. Set up the Candis app or an authenticator app again when you regain access to your smartphone.


Save two-factor authentication for 14 days

You can save a successful two-factor authentication on the current device for 14 days. Select the option for saving the authentication during sign-in. Candis will not ask for another second factor on the same device during the following 14 days.


Security: Only save two-factor authentication on a personal, protected device. Do not select this option on a public or shared computer.


Check your current authentication method

  1. Sign in to Candis.

  2. Open your Profile settings.

  3. Open Account security.

  4. Check the authentication methods connected to your account.

Under Account security, you can also check whether you have already connected an authenticator app.


Use two-factor authentication after losing or replacing your smartphone

Use an alternative authentication method if you no longer have access to your previous smartphone:

  1. Start the sign-in with your email address and password.

  2. Select Try another way.

  3. Sign in by email, SMS, or another available method.

  4. Open your Profile settings after signing in.

  5. Open Account security.

  6. Connect the authenticator app on your new smartphone.

Contact Candis Support from the email address linked to your Candis account if Candis does not show an alternative authentication method.


Reject an unknown sign-in attempt

Select Reject in the Candis app if you receive a sign-in request that you did not start.

Change your Candis password after rejecting an unknown sign-in attempt:

  1. Open your Profile settings.

  2. Open Account security.

  3. Change your password.

  4. Create a new and unique password.

  5. Store the new password in a password manager.

Do not use or share an unexpected authentication code that you receive by email or SMS.

Security: Candis Support will not ask you to share a two-factor authentication code.


Did this answer your question?