Multi factor authentication (MFA) adds a second step to your sign in so a stolen email inbox alone cannot access your firm's data. Nagaris supports passkeys, authenticator apps and SMS codes, with single use backup codes as a safety net.
If your firm requires MFA, you will see the Secure Your Account screen straight after signing in, and you cannot enter the workspace until you have enrolled a method. Your only other option on this screen is Sign out.
You can also enable MFA voluntarily at any time from your Security page.
Passkey: Use your face, fingerprint or device PIN. No codes needed. This is marked Recommended and only appears on browsers that support passkeys. Passkeys are phishing resistant.
Authenticator App: Get a 6 digit code from an app each time you sign in.
Text Message (SMS): Get a 6 digit code sent to your mobile each time you sign in.
Choose Passkey. On the Set Up a Passkey screen, give it a Passkey Name, for example MacBook Pro or iPhone, so you can identify it later.
Click Register Passkey and approve your device prompt, for example Touch ID, Face ID, Windows Hello or a security key. If you dismiss the prompt you will see that passkey registration was cancelled or timed out. Try again.
Choose Authenticator App. On Set Up Authenticator App, scan the QR code with your authenticator app, for example Google Authenticator, Authy or 1Password. Cannot scan? Enter the key shown below the QR code manually.
Click I have scanned the code, then Next.
On Verify Authenticator, enter the 6 digit code from your app and click Verify and Enable. A wrong code shows Invalid code. Please try again.
Choose Text Message (SMS). On Set Up Text Message Codes, enter the Mobile Number that should receive your sign in codes and click Send Verification Code.
On Verify Your Mobile, enter the 6 digit code texted to you and click Verify and Enable. Use Resend code if it does not arrive, or Use a different number to start over.
After enabling an authenticator app, or SMS as your first method, Nagaris shows Save Your Backup Codes. Each code can only be used once, and they are your way in if you lose your phone or passkey. Use Copy or Download to save them as a text file, store them somewhere safe, ideally a password manager, then click I have saved my codes, then Continue. When you are done you will see You are all set, then click Continue to Nagaris.
Once MFA is enabled, after your usual sign in Nagaris shows a verification step.
If you have an authenticator app enrolled, it is shown first. Otherwise passkey is shown first when it is supported and enrolled. If you do not have an authenticator app or passkey, SMS is shown first when it is enabled.
Two Factor Authentication: Open your authenticator app and enter the verification code, then click Verify.
Verify with Passkey: Click Use Passkey and approve the device prompt.
Text Message Verification: Click Text me a code, then enter the 6 digit code and click Verify. Resend code becomes available after a 30 second countdown.
Backup Code: Enter one of your single use backup codes, then click Verify.
Links at the bottom of each screen let you switch between whichever methods you have enrolled, for example Use a passkey instead, Text me a code instead, Use an authenticator app instead or Use a backup code instead, or choose Cancel and sign in again to start over.
Invalid verification code: Authenticator codes rotate every 30 seconds. Wait for a fresh one and check your phone clock is set automatically.
Invalid backup code: Each backup code works exactly once. Try another from your saved list.
Too many attempts: You may see Too many requests. Please try again in a few minutes. Wait before retrying.
Passkey verification was cancelled or timed out: Dismissed or timed out prompts can be retried. Try again.
If you refresh or navigate away during verification your MFA session may expire and you will be sent back to the sign in page. Sign in again to restart verification.
Lost every method, phone, passkey and backup codes: Contact support so the team can reset MFA on your account, then re enrol.