Login Security
boberdoo’s login security feature requires two-factor authentication for any admin, partner or vendor that logs into your system. Two-factor authentication (2FA) is a system that requires verification at two separate points: correct username/password entry and 2FA verification code entry.

How to Enable 2FA in Your Lead System
Navigate to 2FA Settings
Login to your lead system with an admin, partner, or vendor account. From your Lead System home page, navigate to Settings > 2FA Settings. You will see two options for 2FA authentication - Google Authenticator and Email. Using an authenticator app is considered to be more secure than other methods. boberdoo recommends setting up both methods so you have a backup in the event that your authenticator device is unavailable.

Set Up Google Authenticator
First, we will set up 2FA with Google Authenticator. You will need to install the Google Authenticator app on your phone or another mobile device. The app is available for free for iPhone and Android devices in their respective app stores. Download the app before proceeding. Note: Other authenticator apps such as Microsoft Authenticator are compatible with boberdoo 2FA as well. Click Setup to proceed. A QR code will be displayed. Open the authenticator app on your phone. Click the add icon in the app and scan the QR code with your device's camera.

2FA Setup Confirmation

Enter Authentication Codes
A six-digit authentication code will be displayed in your app. Enter the code in the First Authentication Code field. Keep the app open and wait for the code to change (the code changes every 30 seconds). Enter the next code in the Second Authentication Code field. Click Setup Google 2FA. Google Authenticator setup is now complete. Next time you log into your Lead System, you will be prompted to enter the 2FA code from your app. Once authenticated, you will only need to enter the 2nd-factor code every 30 days or whenever you sign in from a new browser or device.

Set Up Email 2FA
Next, we will configure 2FA for email. Click Setup to begin. A verification link will be sent to the email address associated with your Lead System account. If you did not receive the verification email, check your spam folder or click Re-Send Email to try again. Check your inbox for the verification link and click the verification link to complete the setup. Now that you have configured both 2FA options, you may log in to your account with either method.

Email Verification

Login with 2FA
Navigate to your Lead System login page and enter your username and password as you normally would. You will be prompted to select an authentication method - either Email or Authenticator App. In this case, we will choose Email from the dropdown menu. Click Send Confirmation Code.

Verification Confirmation

Complete Authentication
Check your email for the code and enter it here. Click Login to proceed. Upon successful authentication, you will be directed to your Lead System home page. Remember that the authenticator app is the quickest and most secure way to retrieve your 2FA code. Email should only be used if your mobile device is unavailable (lost, stolen, dead battery, etc.).

Managing 2FA Settings
In consideration of using email for 2FA: Do not use the same password for your Lead System that you use for email and enable 2FA on your email account if you don't have it already. If you ever need to reset 2FA authentication methods for use with a new device or email address, return to Settings > 2FA Settings and select Disable on the method you want to change. Never disable both methods at the same time. If you do, you may be locked out of your Lead System and will need to have an administrator assist you. The above rules and setup process can also be applied to any of your partners and vendors when they log into the system.

2FA FAQ
2FA is prompted once every 30 days on the same computer and browser. Using a different computer or browser triggers a new prompt. Admins can view remaining days in the cycle at Settings > 2FA Settings and use the refresh button to reset the countdown.
Two redirect options are available: a soft redirect where users can navigate away, and a hard redirect that forces users to enable 2FA before they can access the system. Users enable 2FA individually via Settings > 2FA Settings.
The authenticator app is recommended over email for enhanced security. boberdoo recommends enabling both methods as backup. Never disable both methods simultaneously as this risks account lockout.
Secure Your Lead System
Two-factor authentication is just one of many security features available in the boberdoo platform.