Note: This feature is currently in beta. The core functionality works as described and we are still polishing details. Small changes to wording, screens, or behaviour may still occur.
How two-factor authentication via the Candis app works
Two-factor authentication, or 2FA, adds a second authentication factor to your email address and password. With our recommended method, Candis sends a push notification to the Candis app on your smartphone.
As soon as you start using the Candis app and log in to the app once, Candis automatically activates push notifications as your second authentication factor. You do not need to change any additional settings in Candis.
Two-factor authentication via the Candis app is stored as the default method for all users of the Candis app. You can still choose another available authentication method during every login.
Please note: Two-factor authentication via the Candis app protects your Candis web login. You use the app to confirm the login in your browser.
Requirements
You need to meet the following requirements to confirm your web login via push notification:
You have installed the Candis app on your smartphone.
You use at least version 2.1 of the Candis app.
You have logged in to the Candis app at least once with your email address and password.
You have access to your smartphone when you log in to Candis in your browser.
You have enabled push notifications for the Candis app in your smartphone settings.
Tip: Check the app version on your smartphone. Update the Candis app in the App Store or Google Play Store if you use a version older than 2.1.
Tip: Enable push notifications for the Candis app on your smartphone. This ensures that you receive login requests immediately on your lock screen or in your notification center.
Confirming your web login with the Candis app
Open Candis in your browser and log in with your email address and password.
Candis displays the message Waiting for your approval.
Open the push notification on your smartphone.
The Candis app opens the Confirm login attempt section.
Check the login details. The Candis app shows the account name, device, and browser used, for example Chrome on Mac OS X.
Tap Confirm if the details match your current web login.
Candis completes the web login in your browser automatically.
You can save the two-factor authentication for 14 days on the device you are using. Select the corresponding option during login. Candis will not request two-factor authentication again on this device for the next 14 days.
Please note: Save two-factor authentication only on personal and trusted devices.
Please note: Tap Reject if you did not initiate the displayed login attempt. This prevents another person from logging in with your credentials. Change your password afterwards.
Using an alternative method when your smartphone is unavailable
You can switch to an alternative authentication method if you do not have access to your smartphone or the Candis app.
You can also choose an alternative authentication method if the Candis app is stored as your default method and you prefer to use another option.
Start the web login with your email address and password.
Select Or try another way on the login page.
Choose an alternative authentication method.
Request the code by SMS or email.
Enter the code on the login page to complete the web login.
Tip: Use this alternative when you cannot access the Candis app. Login via push notification remains the recommended method.
Viewing your 2FA method and last app login in your profile
Your profile shows which two-factor authentication method is stored for your user account. You can also see your most recent login to the Candis app.
Open your profile in Candis.
Check the stored 2FA method.
Check the date and time of your most recent login to the Candis app.
Viewing app usage in user management
As an admin, you can check which team members already use the Candis app in user management.
Open user management.
Find the relevant team member.
Look for the app icon next to the team member.
The app icon shows that the team member already uses the Candis app.
Inviting team members to the Candis app
As an admin, you can invite individual team members or all team members to the Candis app.
Open user management.
Move your cursor over the relevant team member.
Click Invite to app in the menu that appears.
Confirm the invitation in the pop-up window.
You can also invite all team members to the Candis app from the pop-up window.
Using the Candis app to display credit card details
Once you have set up and logged in to the Candis app, Candis also uses the app to securely display credit card details.
When you request to display credit card details in the web application, Candis sends a request to the Candis app. Confirm the request in the app to display the credit card details in your browser.
Examples
Confirming a web login during your working day
You open Candis in your browser, enter your email address and password, and receive a push notification on your smartphone. You check the device and browser in the Candis app and tap Confirm. Candis logs you in to the web application.
Rejecting a login attempt
You receive a push notification even though you are not currently logging in to Candis. You open the Candis app, check the login attempt, and tap Reject. You then change your password.
Displaying credit card details securely
You want to view credit card details in the web application. Candis sends a confirmation request to the Candis app. You confirm the request on your smartphone, and Candis displays the credit card details in your browser.
Please note: You cannot currently confirm credit card payments using the Candis app.
