What is Two-Factor Authentication?
Two-Factor Authentication (2FA) adds an extra layer of security to your Bright account by requiring a verification code in addition to your email address and password each time you log in. 2FA is mandatory across all Bright products.
| Important: 2FA cannot be disabled. You can only change the method used. This guide covers both BrightHub and BrightPay (Cloud) — the setup and reset processes differ between products. |
| BrightHub — 2FA Setup & Management |
The following steps apply to BrightHub and other Bright products that use your BrightHub profile (such as BrightManager, BrightBooks, BrightAP, BrightTax and BrightPropose).
Logging In with 2FA Enabled
With 2FA active on your account, you will see an extra verification step when loging in.
Step 1 — Sign in with your email address and password
Step 2 — Verify Your Login
You will be asked to verify your login. A one-time code will be sent using your configured 2FA method.
Step 3 — Check Your Email or Phone
Retrieve the verification code from your email inbox, authenticator app or SMS.
Step 4 — Enter the Code
Return to BrightHub, enter the code in the verification field, and click Verify.
Changing Your 2FA Method (BrightHub)
You can update your 2FA method at any time from your BrightHub profile.
1. Log in to BrightHub.
2. Click your profile icon (your initials) in the top-right corner.
3. Go to Profile → Security → Change
4. Select your Two-Factor Authentication method and save.
| Note: Disabling 2FA will not be possible. You can only change the method — not turn it off. |
Available 2FA Methods
The table below summarises the available methods and their relative security levels.
| Method | Security Level | What This Means |
|---|---|---|
| Authenticator App (Recommended) | Strongest Option | Recommended for the highest level of account protection possible |
| Email (Default) | Less Secure Option | Simple and reliable. Should only be used when the APP is not an option |
| SMS | Least Secure Option | Convenient, but not recommended where alternatives are available |
Recommended Option: Authenticator App
Authenticator apps generate a time-based code on your device. We strongly recommend the Microsoft Authenticator app. Google Authenticator and Authy also work with any standard TOTP app.
How to Set It Up:
1. Go to Security Settings.
2. Select Enable Two-Factor Authentication.
3. Choose Authenticator App.
4. Download Microsoft Authenticator from the Google Play Store or Apple App Store.
5. Scan the QR code displayed on screen.
6. Enter the 6-digit code shown in the app to confirm setup.
7. Save your backup/recovery codes in a safe place.
Default Option: Email Authentication
A one-time code is sent to your registered email address each time you sign in.
How to Set It Up:
1. Go to Security Settings.
2. Select Enable Two-Factor Authentication.
3. Choose Email and confirm your email address.
4. Enter the verification code sent to your inbox to complete setup.
Not Recommended Option: SMS Authentication
A verification code is sent to your mobile phone by text message.
How to Set It Up:
1. Open Security Settings.
2. Select Enable Two-Factor Authentication.
3. Choose SMS and enter your mobile phone number.
4. Enter the code sent via text message to confirm.
Common Questions
"Why can't I turn off 2FA?"
Bright has enabled mandatory 2FA to protect your financial and client data. It cannot be disabled by you or by Support.
"Is this a bug? I never setup 2FA"
No, this is expected behaviour since this was made Madatory on the 17th of September 2026.
"Can Support turn 2FA off for my organisation?"
No. Mandatory 2FA is a security feature and cannot be disabled. Support can help you choose the simplest method for your team.
"I can't access my email or phone — how do I log in?"
2FA is Mandatory since September 17th 2026. You will require access to either your emails or phone in order to receive the 2FA code that is sent to you.
If you are currently setup to login via an authenticator app and you dont have your phone you should have your recovery codes available to use. These codes obtained when enabling the authenticator method can be used one time and is a great quick and easy way to get around not having access to your phone. Simply enter one of the codes instead of the one normally generated on your app.
In the event that you do not have your phone or access to your recovery codes then an admin or owner may be able to reset this back to email. The same is true if you are set to SMS and you do not have your phone or set to email with no access to emails as someone can reset you to sms or email depending on the scenario.
Admin Steps to Reset a Staff Member's 2FA:
- The admin or organisation owner needs to go into BrightHub
- Once in BrighHub select members on the left hand side of the page.
- Select the manage button next to the Staff member needing to regain access.
- Select ‘Reset 2FA’ from the drop down.
- Then select the Method your staff member would like to use between email and sms.
- If you select Email, When your staff member next logs in they will be emailed the code for their 2FA.
- If you select SMS then the following applies.
- You will be asked to enter the mobile number that will be used for the 2FA
- That number will then be sent a Verification code
- You then must input the code provided to confirm this number is correct and this turns the 2FA method on.
- The next time the Staff member logs in they will get an SMS with their 2FA code to login.
| Admin note: If you are the admin and need your own 2FA reset, you must contact Bright Support directly: brighthubsupport@brightsg.com |
Not Receiving Your 2FA Code? (BrightHub)
If you are using email-based 2FA and the verification code is not arriving, follow these steps before taking any further action.
Step 1 — Check Your Junk or Spam Folder
Verification emails can occasionally be filtered by your email client. Check your junk or spam folder before assuming the code has not been sent.
Step 2 — Do Not Keep Requesting a New Code
Do not repeatedly click to resend the code. Each time you request a new code, the previous one is invalidated. If you request multiple codes in quick succession and then enter one that is no longer valid, you risk triggering a temporary account lockout after five failed attempts. Request the code once, then wait.
Entering too many incorrect codes will lock your account temporarily for 10-30 minutes. Request the code once only, then wait before trying again.
Step 3 — Wait Up to 10 Minutes
Email delivery can be delayed depending on your mail provider or internal infrastructure. Allow up to 10 minutes before taking further action. Continue to check your junk and spam folder during this time. Do not request a new code during this period.
Step 4 — Contact Your Internal IT Team
If the code has still not arrived after 10 minutes and is not in your junk or spam folder, the issue is most likely being caused by your organisation's own email filtering or security systems blocking delivery from Bright.
This is not something Bright Support can resolve on your behalf. Contact your internal IT team and ask them to:
- Check whether emails from Bright are being quarantined or blocked.
- Whitelist the Bright sending domain to allow 2FA codes through noreply@brightsg.com
📌 Note: If you need urgent access and cannot wait for IT to investigate, ask your BrightHub admin to temporarily reset your 2FA method to SMS so you can log in while the email delivery issue is being resolved.
Comments
0 comments
Article is closed for comments.