Skip to content
Help Center

Two-factor authentication and passkeys

How to turn on 2FA in Vigilis with an authenticator app or a passkey, rotate it, regenerate backup codes, add passkeys, and when you can't disable it.

Two-factor authentication (2FA) and passkeys add a second layer of protection to your account, beyond your password. You manage both from your profile at /profile. For a plain-language overview of signing in, see Signing in and securing your account.

Turning on 2FA

Find the Two-Factor Authentication card on your profile and click Enable 2FA. That opens the enrollment page, where you pick one of two methods:

  • An authenticator app (TOTP), which generates a rotating 6-digit code.
  • A passkey (biometrics, a security key, or your device).

If your account has a password, the authenticator app is the default. Passwordless accounts (SSO, social sign-in, or passkey) enroll with a passkey.

Managing 2FA once it’s on

With 2FA enabled, the card lets you:

  • Rotate the authenticator. Set up a fresh authenticator app, for example when you move to a new phone.
  • Regenerate backup codes. Your codes are shown once, so save them somewhere safe. Each code works one time. Regenerating requires your password.
  • Disable 2FA. This also requires your password.

Backup codes are your way back in if you lose your authenticator, so keep them somewhere you can reach without your phone.

If your account has no password

If your organization signs you in with SSO or a passkey and your account has no password, there is nothing to manage in the 2FA card. The card says so.

If your organization requires MFA

When your organization requires MFA for all members, you can’t turn it off. You can still change how you verify: if you need to replace your authenticator, add a passkey first, then rotate the authenticator.

Passkeys

Add a passkey from the Passkeys card, using your device’s biometrics, a security key, or the device itself.

A new passkey is named automatically with the date it was added. There is no rename. To remove a passkey, use its trash icon.

Common questions

How do I turn on two-factor authentication in Vigilis?
Open your profile, find the Two-Factor Authentication card, and click Enable 2FA. You can enroll with an authenticator app (TOTP) or a passkey. If your account has a password, the authenticator app is the default.
I lost my authenticator. How do I get back in?
Use one of your backup codes to sign in. Each backup code works once. Once you're in, regenerate your backup codes and rotate your authenticator so your old device no longer works.
Why can't I turn off 2FA?
If your organization requires MFA, you can't disable it. You can still change how you verify: add a passkey first, then rotate your authenticator if you need to replace it.
Can I rename a passkey?
No. A new passkey is named automatically with the date it was added. There's no rename. To remove one, use its trash icon.

Still stuck?

If your Vigilis account is managed by an IT or telecom provider, they can resolve account and plan questions fastest. You can also reach us directly.

Contact support