Skip to main content

Multi-Factor Authentication (MFA): How to set up and use login security in HRA Hub

This article is for employees and employers using Take Command who need to set up, use, or troubleshoot MFA when logging into HRA Hub.

Written by Jessica T

Multi-Factor Authentication (MFA) adds an extra security step to your HRA Hub login by requiring a one-time code from an authenticator app or email in addition to your password.

What is MFA?

MFA (Multi-Factor Authentication) is a security feature that protects your account by requiring two forms of verification:

  • Your email and password

  • A one-time verification code sent to your authenticator app or email

This helps prevent unauthorized access even if your password is compromised.

When do I set up MFA?

You will set up MFA the first time you log into HRA Hub after account creation or invitation.

During setup:

  • You will be prompted to choose an MFA method

  • You must complete MFA setup before accessing your account

  • Your selected method becomes the default for future logins

How do I set up MFA?

Follow these steps during your first login:

  1. Log in to the HRA Hub sign-in page with your email and password

  2. When prompted, choose your MFA method:

    • Authenticator app (recommended), or

    • Email verification

  3. Complete setup based on your selected method

  4. Enter the one-time code provided

  5. Confirm and finish setup

Once completed, MFA will be required for future logins.

How do I set up MFA using an authenticator app?

If you choose an authenticator app:

  1. Download an app such as:

    • Google Authenticator

    • Microsoft Authenticator

    • Authy

  2. Open the app and scan the QR code shown in HRA Hub

  3. The app will generate a 6-digit code

  4. Enter the code into HRA Hub

  5. Confirm to complete setup

You may also manually enter a setup key if scanning is not possible.

MFA troubleshooting steps

If you are having issues logging in, try the following:

  1. Refresh the login page or restart your browser

  2. Use an updated browser (Chrome is recommended)

  3. Clear cache and cookies

  4. Try an incognito/private window

  5. Disable autofill/password managers temporarily

  6. Switch to another device or browser

  7. Request a new MFA code

  8. Ensure your authenticator app or email is working correctly

If issues persist, you may need to reconfigure MFA or request a reset.

What does NOT happen with MFA?


What if I lose access to my MFA device or authenticator app?

If you lose access to the phone, device, or email account used for MFA — for example, if you get a new phone, lose your authenticator app, or can no longer receive codes — your MFA configuration must be reset by Customer Experience.

You cannot reset MFA yourself from the portal or through a password reset. Contact Customer Experience with your full name and email address — they will verify your identity and reset your MFA so you can complete setup on your new device.

To avoid being locked out when switching devices, set up MFA on your new device before decommissioning the old one, or export your authenticator app's backup codes while access is still available.

MFA does NOT:

  • Replace your password

  • Remove the need for login credentials

  • Guarantee permanent device trust unless cookies are retained

  • Work without a valid email or authenticator setup

Did this answer your question?