Multi-Factor Authentication (MFA) for users

In today’s digital world, securing financial data in expense management solutions is critical. Multi-Factor Authentication (MFA) adds an extra layer of protection by requiring more than just a password to verify user identity. In this article, we’ll cover what MFA is, its role in expense management, and how to set it up in Webexpenses. Want to enhance your security?

  1. What is Multi-Factor Authentication (MFA)?
  2. Setting Up MFA in Webexpenses
  3. Configuring MFA
  4. Using Backup Codes
  5. Logging In with MFA
  6. FAQs

What is Multi-Factor Authentication (MFA)?

Multi-Factor Authentication (MFA), or Two-Factor Authentication (2FA), is a vital security measure that verifies user identity through multiple credentials. It safeguards against hacking, phishing, and compromised passwords.

Setting Up MFA in Webexpenses

In Webexpenses, MFA combines a user’s password with a second authentication factor, typically from an authentication app.

For Administrators:

To enable MFA company-wide or at division levels:

  1. Navigate to Administrators > Company Profile > Security.
Webexpenses system displaying how to turn on MFA in the security section

2. Select ‘Enable Mandatory Multi-Factor Authentication’ and choose user roles to apply MFA.

Webexpenses system displaying how to turn on MFA in the security section

3. Save changes to enforce MFA across selected roles.

Note: Once confirmed, these changes will come into effect for all users with that role against them regardless of the reason they are logging in to the system.

For Individual Users:

To set up MFA for your profile:

  1. Go to My Settings > Security.
  2. Click on ‘Configure MFA’ and follow the prompts.

Configuring MFA

  1. Scan the QR code or enter the provided key into your authentication app (e.g., Google Authenticator).
  2. Verify setup and securely store backup codes provided.
Webexpenses system displaying how to configure MFA with QR code

Using Backup Codes

Store backup codes securely to access Webexpenses if your primary authentication device is unavailable. Regenerate codes via My Settings if lost.

Webexpenses system displaying list of MFA backup codes

Note: If you lose your backup codes you can generate new codes by signing into Webexpenses. Navigate to My Settings > Security and select ‘Regenerate Backup Codes’. This will void all previous codes and provide new ones.

Logging In with MFA

Enter the verification code from your authenticator app to access Webexpenses securely.

Webexpenses system displaying how to enter verification code from authenticator app

Managing MFA Settings:

Administrators can adjust MFA settings under Administration > Company Profile > Security, including adding or removing user roles.

Resetting MFA:

Administrators can reset MFA for users via Administration > Users, ensuring security in case of lost devices.

Webexpenses system displaying how to reset MFA

FAQs

What authentication apps can I use?

Compatible with Google Authenticator, Microsoft Authenticator, Duo Mobile, LastPass Authenticator, and Twilio Authy. 

What if I lose my backup codes?

If you know you have lost your backup codes then log into Webexpenses go to My Settings and select ‘Regenerate Backup Codes’ to create new codes. 

What if I lost my device and backup codes?

If you lose both your device and backup codes then your MFA will need to be reset by your administrator. Contact your administrator and ask them to reset MFA for your user profile.

On the next login, you will either be asked to configure the details again with your new device or go to My Settings and configure your MFA again.

I’m concerned someone has seen my backup codes, what should I do? 

In this situation, login into Webexpenses, go to My Settings and select ‘Regenerate Backup Codes’ to create new ones. This will instantly make any old codes invalid.

How should I store my backup codes?

The best way to store backup securely is in a secure password manager or vault. Tools such as Keeper or LastPass offer secure storage for important information like this.

If you can’t find an answer to your question, get in touch with the Webexpenses team.

Ready to start using the MFA functionality in Webexpenses? Book a demo to learn more today!

Related articles

An image showing the logos of Webexpneses and Traild.

Webexpenses vs. Traild: An Honest Comparison for MYOB Users

Even though people often compare us, Traild isn’t really a competitor to Webexpenses. It’s an accounts payable automation tool that gets loosely bundled in with expense management because of its strong ties to MYOB. If you’ve been comparing them and us, the short answer is this: Traild solves invoice processing, and Webexpenses solves expense management plus invoice processing.  They overlap on one thing and […]

A graphic showing Webexpenses vs Soldo

Webexpenses vs Soldo: UK Expense Management Comparison 2026 

If you’re comparing Webexpenses (that’s us!) with Soldo, it helps to know upfront that we’re not really solving the same problem. So it’s less a question of ‘Webexpenses vs Soldo’ and more a question of which need your business is trying to solve. We’ve built Webexpenses as a dedicated expense management platform, one place for every […]

Close-up view of a modern car interior featuring illuminated digital instrument cluster and dashboard controls. Automotive technology concept showing speedometer, warning display, driving information, and premium vehicle cockpit design in low light conditions.

Everything You Need to Know About HMRC Mileage Rates 2026/27 

The HMRC mileage rate, or if we’re being more formal: the Approved Mileage Allowance Payment (AMAP), is the amount you can pay an employee, tax-free, for using their own vehicle on a business journey.  In other words, rather than reimbursing fuel, insurance and wear and tear separately, HMRC sets a single pence-per-mile figure that covers all of it in […]