Multi-Factor Authentication (MFA) means signing in needs two things: your password and a 6-digit code from an authenticator app on your phone. Even if someone learns your password, they can't get in without your phone.
Some organizations require MFA; others let you turn it on yourself. Either way, the setup is the same.
What you need
An authenticator app on your phone. Any of these work:
- Google Authenticator
- Microsoft Authenticator
- Authy
Install one before you start.
Setting up MFA (web)
- Sign in and open Account Settings.
- Under Two-Factor Authentication (MFA), click Set Up MFA.
- A QR code appears. Open your authenticator app, tap + / Add account → Scan QR code, and point it at the code. (Can't scan? The page also shows a key you can type in manually.)
- Your app shows a 6-digit code. Type it into the Verification Code box.
- Click Verify and Enable MFA.
Save your recovery codes
After setup, BEHCA shows a list of recovery codes. Save these somewhere safe — a password manager, or printed and stored somewhere only you can reach. Each code works once if you ever lose access to your authenticator app.
Logging in with MFA
Signing in (password → authenticator code, Trust this device for 30 days, and using a recovery code on the login screen) is covered in Logging in. If a code is rejected at login, see Login issues.
I lost my phone — what now?
- On the sign-in code prompt, choose Use recovery code instead and enter a saved recovery code.
- Once you're signed in, either generate new recovery codes (below) or reset MFA to pair a new authenticator app.
If you've also lost your recovery codes, contact Support — they can reset MFA on your account so you can sign in and set it up again.
Managing MFA while signed in (web)
These steps are for when you are already logged in on the website. They are not part of the sign-in flow.
Open Two-Factor Authentication management:
- Sign in at
app.behca.com(US) orau.behca.com(Australia). - Go to
/mfa/manage(for exampleapp.behca.com/mfa/manage).
The page title is Two-Factor Authentication. You can return to Account Settings from the link at the bottom.
Generate new recovery codes
Use this when you still have your authenticator app but want a fresh set of recovery codes (for example you used several codes or lost your saved list). This does not change your authenticator pairing.
- On
/mfa/manage, under Recovery Codes, enter your current 6-digit authenticator code. - Click Generate New Recovery Codes.
- BEHCA shows the new codes once. Copy or download them, then confirm you have saved them.
Old unused recovery codes stop working as soon as the new set is generated.
Disable MFA
Only available when your organization does not require MFA for everyone. If MFA is required, the page explains that you cannot turn it off.
- On
/mfa/manage, under Disable MFA, enter your current password. - Click Disable MFA.
Disabling removes your authenticator pairing and recovery codes. You can turn MFA on again later from Account Settings → Set Up MFA.
Reset your MFA (new authenticator app)
Use Reset your MFA from Account Settings when you need a new QR code and authenticator pairing (for example a new phone). This is stronger than generating recovery codes alone:
- Open Account Settings and click Reset your MFA.
- Enter your password to confirm.
- Scan the new QR code and complete setup. You receive a new set of recovery codes.
Resetting invalidates old recovery codes and trusted devices.
If your organization requires MFA, you can reset or regenerate codes, but you cannot disable MFA or leave your account without it.
Common questions
- Do I need MFA on the mobile app too? — MFA is per-account, not per-device. If MFA is on, you'll be asked for a code when signing in on mobile too.
- Can I use SMS instead? — Not currently. BEHCA supports authenticator-app codes only.
- Will I need a code every single time? — Only when you sign in. Tick Trust this device for 30 days to skip the code on that device for a month, and staying signed in avoids re-entering it until your session ends.