Multi-Factor Authentication (MFA) helps protect your ChiroFusion account by requiring a verification code in addition to a username and password when signing in.
Before enabling MFA, the user will need to install an authenticator application on their mobile device. We recommend either:
- Google Authenticator
- Microsoft Authenticator
Both applications are available for download from the Apple App Store and Google Play Store.
Important: MFA can only be enabled for user accounts and is not available for admin accounts.
Enable MFA for a User
- Log in to your ChiroFusion Admin account.
- Navigate to the Users tab.
- Select the user you would like to enable MFA for using the Select User drop-down menu.
- Locate the Enable MFA option in the bottom-right corner of the screen.
- Check the Enable MFA box.
- Click Save.
MFA has now been enabled for that user account.
Complete MFA Setup During Login
The next time the user logs in, they will:
- Enter their username and password.
- Accept the Terms and Conditions.
- Click Log In.
A QR code will then appear on the screen.
Using their authenticator application, the user can either:
- Scan the QR code, or
- Manually enter the provided setup key
Once the account has been added to the authenticator application, a verification code will be generated.
The user should:
- Enter the verification code into the verification field on the login screen.
- Optionally select Remember this device for 30 days if they do not wish to be prompted for a verification code on that device for the next 30 days.
- Click Verify.
Set Up a Backup Phone Number
After successfully entering the verification code, the user will be prompted to add a backup phone number.
This phone number can be used as an alternative verification method if the user no longer has access to their authenticator application.
Enter the desired phone number and complete the verification process when prompted.
Generate and Save Backup Codes
The final step of MFA setup is generating backup codes.
These codes should be stored in a secure location and should only be used if the user cannot access:
- Their authenticator application, and
- Their backup phone number
Important: Each backup code can only be used once.
Once the backup codes have been saved, MFA setup is complete.
Signing In with MFA
After MFA has been configured, users will continue to sign in with their username and password as usual.
If the device is not currently trusted, or if the 30-day trust period has expired, the user will be prompted to enter a new verification code from their authenticator application before accessing ChiroFusion.
Resetting MFA
If a user receives a new phone, loses access to their authenticator application, or needs to reconfigure MFA for any reason, an administrator can reset MFA.
To reset MFA:
- Log in to the Admin account.
- Navigate to the Users tab.
- Select the appropriate user.
- Click Reset MFA.
- Click Save.
The next time the user signs in, they will be prompted to complete the MFA setup process again.
