| Overview |
Two-factor authentication (2FA) adds a second layer of security to your BrightHub login. In addition to your email and password, you will be asked to verify your identity using a code. 2FA is mandatory for all BrightHub accounts and cannot be disabled.
| Logging In With 2FA |
- Go to hub.brightsg.com and enter your email address and password as normal.
- You will be prompted to verify your identity. A verification code will be sent using your current 2FA method.
- Retrieve your code from your authenticator app, email, or SMS (depending on your method).
- Enter the code in the verification field and click Verify.
- Optional — tick Remember this device if you do not want to be asked for a code on this device again.
| Available 2FA Methods |
| Method | Security Level | Notes |
|---|---|---|
| Authenticator App | Most secure | Recommended. Generates a time-based code on your phone. Examples: Google Authenticator, Microsoft Authenticator, Authy. |
| Moderately secure | A code is sent to your registered email address each time you log in. | |
| SMS | Less secure | A code is sent by text message to your mobile number. Convenient but not recommended where alternatives are available. |
| Setting Up or Changing Your 2FA Method |
- Log in to BrightHub.
- Click your profile icon (your initials) in the top-right corner.
- Go to Edit Profile, then select the Security tab.
- Under Two-Factor Authentication, select your preferred method.
- Follow the on-screen instructions to complete setup for your chosen method.
Setting Up an Authenticator App
- Select Authenticator App from the 2FA options.
- Download an authenticator app on your phone if you do not already have one — Google Authenticator, Microsoft Authenticator, and Authy are all supported.
- Scan the QR code displayed on screen using the app.
- Enter the 6-digit code shown in the app to confirm setup.
- Save your backup or recovery codes in a safe place.
| ✔ Tip: The authenticator app method is the most secure option and is recommended for all users handling client financial data. |
| If You Cannot Access Your 2FA Code |
If you are locked out of your account because you cannot complete your 2FA verification, your organisation's Admin or Owner can reset your 2FA method for you. They should:
- Go to Members in BrightHub.
- Find your name in the list and click Manage.
- Select Reset 2FA.
- Choose a new 2FA method for you — either Email or SMS.
- You will then be able to log in using the new method and update your preferences once inside.
| ⚠ Important: If your organisation has enforced mandatory 2FA, you cannot turn it off — you can only change the method you use. |
| Frequently Asked Questions |
Q: Can I turn off 2FA?
A: No. 2FA is mandatory for all BrightHub accounts and cannot be disabled. You can change the method you use but not remove it entirely.
Q: Why am I being asked to set up 2FA when I have never used it before?
A: This is expected behaviour. Bright has enabled mandatory 2FA to protect your account and client data. All new and existing users are required to set it up.
Q: Can I use the same authenticator app for multiple accounts?
A: Yes. Most authenticator apps support multiple accounts simultaneously.
Q: I have a new phone — how do I transfer my authenticator app?
A: Log in using your email 2FA method, then go to Security Settings and set up the authenticator app on your new device.
Comments
0 comments
Article is closed for comments.