Multi-Factor Authentication (MFA) for users

In today’s digital world, securing financial data in expense management solutions is critical. Multi-Factor Authentication (MFA) adds an extra layer of protection by requiring more than just a password to verify user identity. In this article, we’ll cover what MFA is, its role in expense management, and how to set it up in Webexpenses. Want to enhance your security?

  1. What is Multi-Factor Authentication (MFA)?
  2. Setting Up MFA in Webexpenses
  3. Configuring MFA
  4. Using Backup Codes
  5. Logging In with MFA
  6. FAQs

What is Multi-Factor Authentication (MFA)?

Multi-Factor Authentication (MFA), or Two-Factor Authentication (2FA), is a vital security measure that verifies user identity through multiple credentials. It safeguards against hacking, phishing, and compromised passwords.

Setting Up MFA in Webexpenses

In Webexpenses, MFA combines a user’s password with a second authentication factor, typically from an authentication app.

For Administrators:

To enable MFA company-wide or at division levels:

  1. Navigate to Administrators > Company Profile > Security.
Webexpenses system displaying how to turn on MFA in the security section

2. Select ‘Enable Mandatory Multi-Factor Authentication’ and choose user roles to apply MFA.

Webexpenses system displaying how to turn on MFA in the security section

3. Save changes to enforce MFA across selected roles.

Note: Once confirmed, these changes will come into effect for all users with that role against them regardless of the reason they are logging in to the system.

For Individual Users:

To set up MFA for your profile:

  1. Go to My Settings > Security.
  2. Click on ‘Configure MFA’ and follow the prompts.

Configuring MFA

  1. Scan the QR code or enter the provided key into your authentication app (e.g., Google Authenticator).
  2. Verify setup and securely store backup codes provided.
Webexpenses system displaying how to configure MFA with QR code

Using Backup Codes

Store backup codes securely to access Webexpenses if your primary authentication device is unavailable. Regenerate codes via My Settings if lost.

Webexpenses system displaying list of MFA backup codes

Note: If you lose your backup codes you can generate new codes by signing into Webexpenses. Navigate to My Settings > Security and select ‘Regenerate Backup Codes’. This will void all previous codes and provide new ones.

Logging In with MFA

Enter the verification code from your authenticator app to access Webexpenses securely.

Webexpenses system displaying how to enter verification code from authenticator app

Managing MFA Settings:

Administrators can adjust MFA settings under Administration > Company Profile > Security, including adding or removing user roles.

Resetting MFA:

Administrators can reset MFA for users via Administration > Users, ensuring security in case of lost devices.

Webexpenses system displaying how to reset MFA

FAQs

What authentication apps can I use?

Compatible with Google Authenticator, Microsoft Authenticator, Duo Mobile, LastPass Authenticator, and Twilio Authy. 

What if I lose my backup codes?

If you know you have lost your backup codes then log into Webexpenses go to My Settings and select ‘Regenerate Backup Codes’ to create new codes. 

What if I lost my device and backup codes?

If you lose both your device and backup codes then your MFA will need to be reset by your administrator. Contact your administrator and ask them to reset MFA for your user profile.

On the next login, you will either be asked to configure the details again with your new device or go to My Settings and configure your MFA again.

I’m concerned someone has seen my backup codes, what should I do? 

In this situation, login into Webexpenses, go to My Settings and select ‘Regenerate Backup Codes’ to create new ones. This will instantly make any old codes invalid.

How should I store my backup codes?

The best way to store backup securely is in a secure password manager or vault. Tools such as Keeper or LastPass offer secure storage for important information like this.

If you can’t find an answer to your question, get in touch with the Webexpenses team.

Ready to start using the MFA functionality in Webexpenses? Book a demo to learn more today!

Related articles

An AP person frustrated at his expenses process, rubs his eyes.

Shadow Spend and Non-PO Invoices: How AP Automation Software Fixes the Problem Nobody Talks About 

An invoice lands in your queue: no PO, no budget code, no prior approval. Someone, somewhere in the company, seemingly, made a handshake deal. The supplier delivered. And now it’s your problem. That’s shadow spend in AP. And unlike the version that shows up in expense claims, this one arrives already spent, already owed – and already awkward.  It’s not a small or occasional […]

A person using one of our Corporate Cards to pay for goods.

Cashback on Corporate Cards: Why Unlimited Returns Aren’t Too Good to Be True 

Big news: we’re introducing cashback on our Corporate Cards. And we’re doing it differently from everyone else in the UK market. While most providers cap your earnings or attach qualifying conditions, we’re launching up to 0.75% (depending on your pricing tier) unlimited cashback on every transaction made with your Webexpenses Card.  No thresholds, no category restrictions, no caps tied to your subscription tier.  Now, if you’re an accountant or finance professional, your immediate reaction is probably healthy scepticism. […]

Frustrated CFO thinking about solutions to shadow spend

Shadow Spending: The CFO’s Guide to Protecting Financial Credibility

Picture the scene: A finance function that runs cleanly, month on month. The close lands on time. The forecasts resemble what eventually unfurls in reality. The board pack is on point. For most CFOs, that version exists mostly in theory.  What gets in the way is rarely one big thing. It’s the slow accumulation of small ones – ‘a thousand cuts,’ as the cliché […]