Multi-Factor Authentication (MFA) adds an extra layer of security to your Xapien account by requiring you to log in with your username and password plus a time-sensitive code from an authenticator app.
Note: MFA is only available for users who log in with a username and password. If your organisation uses Single Sign-On (SSO), you will not see the MFA option in Xapien. Your organisation can choose to implement MFA through their SSO provider.
Setting up MFA for your account
By default, MFA is disabled. Any user can choose to enable it for their own account.
To set up MFA:
Click on your initials in the bottom-left corner of the platform.
Open Settings.
Select the Account security panel.
Follow the on-screen instructions to link your authenticator app (e.g. Microsoft Authenticator, Google Authenticator).
Enter the time-sensitive code from your authenticator app to confirm setup.
Once enabled, you will be asked to enter a code from your authenticator app each time you log in.
Please save the recovery codes provided when setting up MFA. If you're unable to provide a time-sensitive code, a recovery code can be used to access your account.
Enforced MFA
Organisation administrators can choose to enforce MFA for all users in their organisation. When enforced MFA is enabled:
New users will be required to set up MFA when their account is created.
Existing users who have not yet set up MFA will be prompted to do so the next time they log in. They will not be able to proceed until MFA is configured.
If your organisation requires enforced MFA, this is managed by Xapien on your behalf:
If you're on a Pro or Enterprise plan, please contact your Customer Success Manager.
If you're on a Base plan, you can reach out to customer support via the help widget, or contact Customer Success.
For details on how to access support, see: Where can I find Help?
Supported authenticator apps
MFA in Xapien works with any authenticator app that supports time-based one-time passwords (TOTP), including:
Microsoft Authenticator
Google Authenticator
Authy
1Password
Important: MFA via SMS is not supported. You will need access to an authenticator app on your mobile device to complete the MFA setup and login process.
Can I disable MFA after setting it up?
If MFA is optional for your organisation, you can disable it from the Account security panel by selecting Reset your MFA.
If your organisation has enforced MFA, it cannot be disabled by individual users.
What if I lose access to my authenticator app?
You can still access your account using a recovery code. This will prompt you to set up MFA again.
If you don't have access to your recovery codes, please contact your Customer Success Manager or customer support for assistance with account recovery.
Does MFA apply when using SSO?
No. Users who log in via SSO will not see the MFA option in Xapien.
If your organisation uses SSO and requires MFA, this should be configured through your SSO provider.


