Configure two-factor authentication
Two-factor authentication (2FA) protects your admin login to the Magnus Box Web Portal. With 2FA on, a stolen password alone isn't enough to get into the portal that controls all your clients' backups. We strongly recommend turning it on for every admin account.
You can use either method, or both:
| Method | What you need |
|---|---|
| TOTP (one-time codes) | Any authenticator app, for example Microsoft Authenticator, Google Authenticator or Bitwarden |
| FIDO2 WebAuthn | A hardware security key (for example a YubiKey), Windows Hello (needs a TPM), or Android screen lock |
Note: Button and menu names below are from the standard Web Portal. If your portal uses partner branding, a few labels may look slightly different.
Set up TOTP
- In the Web Portal, click your admin name in the top right and choose My account.
- Next to Two-factor authentication (TOTP):, switch the toggle from Not required to Required. A dialog titled TOTP opens. You may also see a "TOTP code regenerated" notice.
- Add the account to your authenticator app in one of two ways:
- Scan the barcode image in the dialog with the app.
- Or, if the image doesn't show or you'd rather add the account by hand, click Copy next to the
otpauth://value and paste it into the app.
- Under Enter your six-digit code below, type the code the app shows and confirm.
- Click Save changes on the My account page.
- Sign out and sign back in to check that the portal now asks for a code.
To move TOTP to a new phone, switch the toggle back to Not required and save, then switch it to Required again and scan the new QR code with the new phone.
Set up FIDO2 WebAuthn
WebAuthn only works when the Web Portal is opened over HTTPS, in a current browser.
- Click your admin name in the top right and choose My account.
- Next to Two-factor authentication (FIDO2 WebAuthn):, switch the toggle to Required.
- In the list of registered keys, click + to add one, and pick the authentication method if you're asked.
- Follow your device's prompts, for example touch the security key or confirm with Windows Hello.
- Click Save changes.
To replace a key, add the new one with +, then select the old one and remove it with −. You can rename a key with the pencil button. To stop using WebAuthn, switch the toggle back to Not required and save.
Notes:
- Older U2F hardware keys also work with WebAuthn. If you registered a U2F key in the past, register it again as a WebAuthn key.
- Apple Face ID and Touch ID aren't supported, and neither is Internet Explorer 11.
If an admin loses their second factor
If an admin can't sign in because they lost their phone or security key, email support@magnusbox.com to get access back.