Skip to main content

Setting up two-factor authentication (2FA)

How to set up 2FA on your Breathe account

Written by Ben Willis

This guide is for Employees.

Two-factor authentication (2FA) adds an extra layer of security to your Breathe account. It asks for a quick second step when you sign in (usually a code from an app on your phone) to verify it's really you.

This guide shows you how to set up 2FA so your account stays safe and secure.

Mandatory 2FA update: From 25 August 2026, we'll begin turning on mandatory 2FA for Admin and HR accounts in batches. If you hold one of these roles, set it up now so you're good to go ahead of time.

Enabling 2FA

Depending on your role and company settings, 2FA may be turned on automatically or made optional:

  • Required by your company: If an Admin makes 2FA mandatory for your role or company-wide, you'll be prompted to set it up the next time you sign in.

  • Automatic HR enrolment: 2FA is automatically switched on for HR users as soon as your company starts its paid Breathe subscription, or when an employee is granted HR permissions (an on-screen notification will inform you of the update).

  • Optional setup: If 2FA is optional in your company, you can still choose to enable it yourself by going to Profile > User preferences and turning on the 2FA toggle.


Setting up 2FA

Step 1: Sign in to Breathe

Once 2FA is enabled, sign in to your Breathe account. You'll see setup instructions on screen, including a QR code and a manual setup key.

Note: Before scanning anything, make sure to delete any old or duplicate Breathe entries from your authenticator app to avoid setup conflicts.

Step 2: Download an authenticator app

Download an authenticator app on your phone from the App Store or Google Play Store (such as Google Authenticator or Microsoft Authenticator).

If you cannot use a mobile device, you can use a browser extension or desktop authenticator on your computer instead (like a browser-based password manager or authenticator extension). See the FAQs section below for more details.

Step 3: Scan the QR code

Open your authenticator app, tap the option to add a new account, and scan the QR code shown on your Breathe screen.

Before scanning, make sure there are no old or duplicate entries of your Breathe account in the authenticator app.

Step 4: Enter your code

Type the code generated by your app into the code field on your Breathe screen. Make sure to enter the code straight away before it refreshes.

Every time you sign in from now on, you'll enter your normal password, followed by the fresh code from your authenticator app.


How to switch 2FA off as an employee

If 2FA is not required across your whole company, you can manage 2FA for your own account:

  1. Go to your Profile > User preferences.

  2. Toggle the Enable 2FA setting off.

Note: If the Enable 2FA option is greyed out and set to 'On', 2FA has been made mandatory at the account level or for your user role, so it cannot be turned off individually.

If you are an Admin or HR user and attempt to turn 2FA off, an on-screen warning will remind you that 2FA will soon be mandatory for your role.

(Though you can turn it off, we always recommend keeping 2FA active to protect your data.)


Troubleshooting persistent 2FA issues

If you're having trouble signing in, try these quick steps:

  • Remove old accounts: Delete any previous or duplicate Breathe entries from your authenticator app.

  • Check time settings: Ensure your phone's time zone settings are set to Automatic so codes stay in sync.

  • Try a fresh code: Wait for your app to generate a brand new code and try the setup process again.

  • First-time mobile app logins or resets: If you are signing in to the People Portal mobile app for the first time (or after a password/2FA reset), tap Set Up in Browser on the screen. You must complete your initial sign-in on a web browser first before returning to the app.

  • Type codes without spaces: Authenticator apps often show spaces (e.g. 123 456) for easy reading. Enter the numbers directly into Breathe without spaces.


FAQs

Q: What if I cannot download an authenticator on my phone?

A: If you cannot install an app on your phone, you can use a browser extension or desktop app on your computer.

  • Password managers: Many password managers have built-in authenticator tools that generate codes directly in your browser.

  • Browser extensions: You can search your web browser's extension store (such as Chrome, Firefox, or Edge) for a browser-based authenticator.

Simply search your browser’s extension store or password manager settings to set up 2FA directly on your computer.

Q: I can't scan the QR code

A: Click the Can't scan QR code button to get your setup key. On your authenticator app, type your full email address along with your setup key (no hyphens needed).

Here is an example setup key (you'll need to enter the unique key shown on your own screen):

D52QD-NSFKS-RRPNR-SPYGM-QQQY3-HLSUQ-UXQ6O-4TKV2-DGYUG-ZFS7M-KA

If prompted for a key type, select Time based.

Q: I have a new device. How do I log in?

A: Ask your HR team to reset 2FA on your Breathe profile. You can then set it up again on your new device.

Before setting up your new device, remove any existing Breathe accounts from your authenticator app. Make sure to use a web browser rather than the mobile app for the reset process.

Q: Why is my 2FA code not working?

A: Your code might not work if your phone's time zone settings are incorrect. If your device isn't set to automatic time, it can cause your codes to fall out of sync.

To fix this, change your phone's time zone settings to automatic and try entering the code again.

Q: Why does Breathe say my code is wrong?

A: Check if there's a space in the middle of your code. Authenticator apps often show codes with a space (like 123 456) to make them easier to read. When you enter your code into Breathe, make sure to type the numbers together without spaces.

Q: Should I use Single Sign-On (SSO) and 2FA together?

A: Yes, we recommend using both. While SSO makes signing in easy, pairing it with 2FA gives your account an extra layer of protection if a password is ever compromised. Find out more about SSO here.

Still have questions?

Please get in touch with your HR team.

Did this answer your question?