Skip to main content

Managing two-factor authentication (2FA)

How to configure 2FA for employees within your Breathe account

Written by Ben Willis

This guide is for Admin and HR users.

Two-factor authentication (2FA) gives your company's Breathe account an extra layer of protection by requiring a second verification step during sign-in. As an Admin, you can choose who needs 2FA across your organisation. If you're an HR user, you can help employees reset their 2FA if they get stuck or get a new device.

Mandatory 2FA update

From 25 August 2026, we'll begin turning on mandatory 2FA for Admin and HR accounts in batches. Set it up now so you're good to go ahead of time.

Why 2FA matters

Passwords can sometimes be guessed, leaked, or stolen. 2FA stops unauthorised logins by asking for a quick second step (a code from a mobile app or browser extension) when signing in. Even if someone gets hold of a password, they will not be able to sign in without that unique code.

Need help setting up your own account? Read our step-by-step guide on How to set up two-factor authentication (2FA).


Finding your account Admin

If you need help changing 2FA settings across your company, you may need to reach out to your primary account Admin.

To find out who holds the main Admin role in your company:

  1. Go to People > Our people.

  2. Look at the Status & permissions column next to each employee's name.

  3. Find the user marked with the 'A' icon.

Choosing 2FA settings for your company

By default, 2FA is turned off for all employees. The Admin can choose which roles need 2FA.

(Note: Only users with Admin permissions can change these company-wide settings.)

  1. Go to Configure > Settings > Security > Two-factor authentication.

  2. Choose who needs 2FA:

  • Everyone: Turn this toggle On to require 2FA for all employees across the company.

  • Individual roles: Use the toggles to turn 2FA On or Off for HR users, Line managers, or Finance users.

Note: To include general employees or team members, you must select Everyone. We'll begin turning on mandatory 2FA for Admin and HR accounts in batches starting 25 August 2026.

First-time app logins or 2FA resets: If an employee logs into the People Portal mobile app for the first time (or after resetting their password or 2FA), they'll see a 'Two-Factor Authentication Required' screen. Ask them to tap Set Up in Browser to complete their initial sign-in on a web browser first before returning to the app.

What happens when you turn 2FA on?

When 2FA is turned on at the account level, all affected users will be prompted to set it up the next time they sign in. Even if an Admin toggles the 2FA switch on and off in quick succession, affected users will still need to complete the setup process to log in.

Note: If an Admin turns 2FA off across the account, individual employees who already set it up can turn it off in their user preferences once signed in.

Once 2FA is active, employees must enter their code every time they sign in, even if they log in multiple times a day.


Checking who has set up 2FA

Want to see which employees have turned on 2FA? You can run a quick report to check their status.

  1. Go to Reports > HR Reports > Two Factor Authentication (2FA).

  2. View the list to see who has active 2FA enabled on their account.

You can click any column header, like 2FA enabled, to sort the report and quickly see who has set up 2FA and who still needs to.


Turning off 2FA across your account

If an Admin turns off 2FA in company settings, it removes the mandatory requirement across the company.

However, turning off account-wide 2FA will not automatically remove 2FA for individual users who have already set it up.

2FA will stay active on their accounts until they choose to turn it off in their individual user preferences.

Important note on turning off 2FA: When an Admin or HR user toggles 2FA off, an on-screen warning will appear to remind you that mandatory 2FA is rolling out for all Admin and HR accounts starting 25 August 2026.

(We strongly recommend keeping 2FA enabled to protect your data and stay ahead of this upcoming requirement.)


How to switch 2FA off as an employee

If 2FA is not required across your whole company, you can manage 2FA for your own account:

  1. Go to your Profile > User preferences.

  2. Toggle the Enable 2FA setting off.

Note: If the Enable 2FA option is greyed out and set to 'On', 2FA has been made mandatory at the account level or for your user role, so it cannot be turned off individually.

If you are an Admin or HR user and attempt to turn 2FA off, an on-screen warning will remind you that 2FA will soon be mandatory for your role.

(Though you can turn it off, we always recommend keeping 2FA active to protect your data)


Resetting 2FA for an employee

If an employee gets a new device, loses their phone, or locks themselves out of their authenticator app, an Admin or HR user can reset their 2FA settings.

  1. Go to the employee's Profile.

  2. Click the User access tab.

  3. Click Reset 2FA.

Note: If a user has never signed into Breathe, the User access tab will not be visible on their profile.

The next time the employee signs in, they'll be prompted to set up 2FA again. If they're using the mobile app, they can tap Set Up in Browser to complete this setup


Troubleshooting employee 2FA issues

If an employee is having trouble signing in or setting up 2FA, try these troubleshooting steps:

  • First-time app logins or 2FA resets: If an employee logs into the People Portal mobile app after resetting their 2FA or password, they'll see a 'Two-Factor Authentication Required' screen. Ask them to tap Set Up in Browser to complete their initial sign-in on a web browser first before returning to the app.

  • Remove old accounts: Ask them to delete any previous or duplicate Breathe entries from their authenticator app before scanning a new QR code.

  • Check time settings: Make sure their phone's time zone settings are set to Automatic so codes stay in sync.

  • No spaces in codes: Ensure they type the code numbers together without any spaces (e.g. 123456 instead of 123 456).

  • Browser issues: Ask the employee to clear their browser's cache and cookies, or try signing in using a private or incognito browsing window.

  • Password reset attempts: Advise employees not to repeatedly click the 'Forgot password' link while waiting for admin assistance, as this can disrupt the account recovery process.

FAQs for Admins & HR

Q: An employee got a new phone. How do I help them sign in?

A: Reset their 2FA from their profile (Profile > User access > Reset 2FA). Ask them to remove any old Breathe entries from their authenticator app before they scan the new QR code on a web browser.

Q: Why is an employee prompted for 2FA again after resetting their password?

A: If an employee resets their password, switches devices, or logs in via a mobile app, they may be asked to confirm setup again. Ask them to complete the sign-in step on a web browser first to resolve this.

Q: What if an Admin cannot manage or disable 2FA settings?

A: If you have Admin permissions but cannot access or change 2FA settings, reach out directly to Breathe support for help.

Q: Can employees use desktop authenticators?

A: Yes. If an employee doesn't have a mobile device, they can use a desktop app or browser extension (like Authy or the Chrome Authenticator extension) on their computer.

Q: Should we use Single Sign-On (SSO) and 2FA together?

A: Yes, we recommend using both. Single Sign-On (SSO) makes signing in effortless, while 2FA provides crucial extra protection if a password is ever compromised. Find out more about SSO here.

Q: How long can I stay signed in before 2FA times me out?

A: For security, sessions automatically time out after 60 minutes of inactivity. You'll just need to sign in again with your password and 2FA code.

Still need a hand?

If an employee is still stuck after trying these troubleshooting steps, as an Admin or HR user, drop us a message using the widget at the bottom right of your screen.

To help us fix things faster, please have these details ready:

  • The email address of the affected employee.

  • The exact error message they're seeing.

  • Whether they're using a web browser or the People Portal mobile app.

Did this answer your question?