The second sign-in step
Sign in to the ERP with your password and a six-digit code from an authenticator app, keep your recovery codes, and set the school's policy.
The second sign-in step protects an ERP account even if its password becomes known. After the password, the ERP asks for a six-digit code from an authenticator app on your phone. The administrator always signs in this way. Other users do when the administrator requires it for them or for their role, and anyone may turn it on for themselves. It works on the Cloud and Offline editions.
This step is for signing in to the ERP workspace. The Parent and Staff portals and apps have their own sign-in.
Before you start#
- A smartphone with an authenticator app. Google Authenticator and Microsoft Authenticator are free; any standard authenticator app works.
- Your ERP password.
Set it up#
You are asked to set it up at sign-in when it is required for you. You can also start it yourself.
- Select the shield button (Sign-in security) at the bottom of the sidebar, then Set up now. If the ERP asked you at sign-in, you are already on this screen.
- On your phone, open the authenticator app and choose Add › Scan a QR code. Scan the code on the screen.
- If you cannot scan it, choose Enter a setup key in the app and type the key shown under the code.
- Type the six-digit code the app now shows into Code from the app.
- Select Turn on.
- The Recovery codes window opens. Select Download as a text file, or write the codes down.
- Select I have saved these codes.
Sign in with it#
- On the sign-in page, enter your login ID, password and the security answer, and select Sign in securely.
- The Second sign-in step window opens. Open the authenticator app and type the current six-digit code for JPRAXC School ERP.
- Select Verify and sign in.
If your phone is not with you, type one of your recovery codes instead. Each recovery code works once. After you use one, the ERP tells you how many are left.
Make new recovery codes#
- Select Sign-in security in the sidebar.
- Select Make new recovery codes.
- Enter your password and select Make new codes.
- Save the new codes. The old ones stop working.
Turn it off#
If the second step is not required for you, you can turn it off: Sign-in security › Turn off the second step, then enter your password. The button does not appear when the school requires the step for you, and the administrator can never turn it off.
For the administrator: choose who must use it#
- Open Users & Control › Access control.
- In the Second sign-in step panel, choose Who else must use it:
- Roles that can change fees, payroll or accounts
- Everyone who signs in to the workspace
- No other role (each user may still turn it on)
- In Days to set it up, enter how many days people have before it becomes compulsory.
- Select Save policy.
Until that date, people covered by the policy are reminded when they sign in. After it, the workspace asks them to set it up before anything else.
The table under the policy lists every user with their role, sign-in mode, whether the step is required, and whether it is on.
For the administrator: require it for one user#
- When creating a user, choose Sign-in › Password + authenticator app.
- For an existing user, select Require the app in the Second sign-in step table, or Sign-in mode in Roles & users. Select Password only to take the requirement away.
The user is asked to set up the app at their next sign-in.
For the administrator: a user lost their phone#
- Open Users & Control › Access control.
- In the Second sign-in step table, select Reset second step on the user's row and confirm.
The user signs in next with the password only and is asked to set up the app again on their new phone.
Good to know#
- The code changes every few seconds in the app. Type the code that is showing now.
- The phone's clock must be set to automatic time, or the codes will not match.
- Only the administrator can reset another user's second step.
Troubleshooting#
| Symptom | What to do |
|---|---|
| That code is not right | Type the code currently showing in the app, without spaces. Check that the phone's date and time are set automatically. |
| The ERP asks you to sign in again | The sign-in took too long. Start again from the sign-in page. |
| You have a new phone | Sign in with a recovery code, then ask the administrator to select Reset second step for you, and set the app up on the new phone. |
| The set-up screen has no Cancel or Later button | The step is compulsory for your account. Complete the set-up to open the workspace. |
