# Two-factor authentication

## Two-factor authentication at a glance

The **2-Factor authentication** configuration screen is where you review user
two-factor choices, trusted devices—the device records associated with sign-ins—and modification
history—the record of changes made by users on this screen.

| If you need to… | Go to |
|---|---|
| Review or change user two-factor choices and code-recipient choices | [Maintain user two-factor settings](#maintain-user-two-factor-settings) |
| Review signed-in devices | [Review trusted devices and modifications](#review-trusted-devices-and-modifications) |
| Read changes made on the configuration screen | [Review trusted devices and modifications](#review-trusted-devices-and-modifications) |
| Resolve a failed save or unavailable action | [When a setting or device action does not work](#when-a-setting-or-device-action-does-not-work) |

## Before you start

**Prerequisites**

- You can open the **2-Factor authentication** configuration screen.
- Editing permission determines whether **Save** and **Save and Close** are available for changes.
- User rows and their checkboxes appear when the user details are available.
- The **Last Modifications** area appears when the configuration has a company identifier.
- Device actions depend on the state shown for each device.

## Find the Two-factor authentication screen

**Prerequisites**

- You are signed in and can open the configuration area.

**Steps**

1. Open the **2-Factor authentication** configuration entry.
2. Confirm that the address is `/configuration/2factor-authentications`.

![Confirm the configuration title, tabs, and save controls at the top of the screen.](https://atloriaassets.blob.core.windows.net/assets/a438221c-c1af-407c-b9e6-a56c986db846/cc1450adb5d27a17faffa44ef20a91cb.png)

**Result:** The **2-Factor authentication** screen opens with the two-factor settings and
the **Trusted devices** tab available.

## Understand the screen and its fields

The screen groups user two-factor choices, trusted-device details, and modification history
into separate tabs and panels.

| Area | What you can review | When it appears |
|---|---|---|
| **2-Factor authentication** | **User**, **Apply 2 factor authentication**, **Send verification code**, **By mail**, **Y/N**, **To admin.**, and **To user** | When the two-factor tab is active and user details are available |
| **Trusted devices** | **Device name**, **Trusted machine**, **Location**, **First login at**, and **Last login at** | When the trusted-devices tab is active |
| **Last Modifications** | A chronological history of actions performed by users | When the configuration has a company identifier |

The two-factor table uses **By mail** for both child columns. The visible grouped header also
shows **Y/N** and **By SMS**, while the mounted child columns carry the **By mail** caption.
The trusted-device columns are read-only. The screen does not provide editable text, date, or
numeric fields.

The trusted-devices table includes a **User** column and displays `Count: 288`. An icon-only
**Refresh** control is available.

The **Last Modifications** panel includes the text `The audit log provides you with a chronological
sequence of actions performed by the users` and dated history entries.

![Review the user rows and grouped two-factor headers before changing a setting.](https://atloriaassets.blob.core.windows.net/assets/a438221c-c1af-407c-b9e6-a56c986db846/a1f4670862d7e3b94c6e8433df48d091.png)

## Maintain user two-factor settings

Change the settings shown in the user rows here.

**Prerequisites**

- The **2-Factor authentication** tab is active.
- User details are available.
- Editing is allowed, and **Save** or **Save and Close** is enabled after a change.

**Steps**

1. In the user row, select the checkbox under **Apply 2 factor authentication**.
2. Review the resulting email-code choice under **By mail**.
3. Select the recipient checkbox under **To admin.** or **To user** when two-factor authentication
   is enabled for that user.
4. Use the all-user checkboxes when the same choice applies across the user rows. The admin/user
   recipient checkboxes keep the two recipient choices mutually aligned.
5. Choose one save action:

   | If you need to… | Select |
   |---|---|
   | Save the changes and remain on the screen | **Save** |
   | Save the changes and leave the screen | **Save and Close** |

6. Read the result message. A successful save uses `Your request was completed successfully`.
7. If the save is rejected, read `An error occurred while processing your request` and return to
   the changed settings before trying again.

**Result:** The selected two-factor and recipient choices are submitted, and either the screen
remains open or it closes according to the save action you selected.

## Review trusted devices and modifications

Use **Trusted devices** to review device records associated with sign-ins, and use **Last
Modifications** to read changes made by users on this screen.

**Prerequisites**

- The **2-Factor authentication** screen is open.
- The configuration has a company identifier if you need to read **Last Modifications**.

**Steps**

1. Select **Trusted devices**.
2. Review the columns **Device name**, **Trusted machine**, **Location**, **First login at**, and
   **Last login at**.
3. Choose the applicable **Last Modifications** action:

   | Panel state | Reader action |
   |---|---|
   | Available | Select **Last Modifications**. |
   | Unavailable | Continue with the trusted-device review. |

4. If the panel is available, read the dated entries in the history panel.

![Review the trusted-device columns and device rows.](https://atloriaassets.blob.core.windows.net/assets/a438221c-c1af-407c-b9e6-a56c986db846/e5959fc6d1ef49bc878ed14c9dbd127b.png)

![Read the dated entries under Last Modifications.](https://atloriaassets.blob.core.windows.net/assets/a438221c-c1af-407c-b9e6-a56c986db846/c752481c1fc993ad09099fdab9ab14b7.png)

**Result:** The screen shows the trusted-device details and, when **Last Modifications** is
available, its dated history.

## Handle trusted-device actions

Device actions depend on whether the selected row is marked as a trusted machine.

**Prerequisites**

- The **Trusted devices** tab is open.
- A device row is visible in the **Trusted devices** tab.

**Steps**

1. Select **Untrust** for a trusted device or **Delete** for a device that is not trusted to open
   the corresponding confirmation.

   | If the device is… | Select |
   |---|---|
   | Trusted | **Untrust** |
   | Not trusted | **Delete** |

2. Select **Cancel** to close the confirmation without changing the device.
3. Read the confirmation question for the action you selected:

   | Action | Confirmation question |
   |---|---|
   | **Untrust** | `Are you sure you want to untrust this device?` |
   | **Delete** | `Are you sure you want to delete this device?` |

**Result:** Selecting **Untrust** or **Delete** opens the corresponding confirmation, and
selecting **Cancel** closes it without submitting the action.

## When a setting or device action does not work

| What you see | What it means | What to do |
|---|---|---|
| `An error occurred while processing your request` | The save request was rejected. | Review the changed settings and try the enabled save action again. |
| **Save** or **Save and Close** is unavailable | Editing is not allowed, or no change is available to save. | Review your access and make a change before selecting a save action. |
| User checkboxes are not available | User details are not available for the two-factor table. | Remain on the screen and work from the user rows when they appear. |
| **Last Modifications** is not available | The configuration does not have the company identifier required for that panel. | Continue with the two-factor or trusted-device tabs. |
| A device action is not available | The row state does not expose that action. | Use the action that matches the state shown for the row. |

The confirmation wording is available when its corresponding dialog opens. The save success
message is `Your request was completed successfully`.

## Out of scope

The following confirmation titles belong to the corresponding two-factor confirmation states,
not to the trusted-device actions described above.

| Message | Scope |
|---|---|
| `Enable 2FA for your account` | Enable confirmation state |
| `Disable 2FA for your accounts` | Disable confirmation state |

## What to do next

After reviewing the tables or saving a change, stay on the screen to review the updated choices,
or use **Save and Close** when you have finished and want to leave it.

**Result:** Your configuration review ends on the updated screen or after **Save and Close**
leaves it.
