← Back to Articles

Knowledgebase Article

Setting Up Multi-Factor Authentication

Category: Configuration | Module: OfficePro | Created: 9/5/2026 | Last Updated: 9/5/2026

Multi-factor authentication (MFA) asks for a second piece of proof after the password, so a stolen or guessed password is not enough on its own to reach patient records. OfficePro offers two methods, and each user sets up their own.

The two methods

A user can set up both. If both are enrolled, the authenticator app is offered first and the text message is available as a fallback.

Set up your own account

  1. Click Account at the top right of any page.
  2. Find Account Security Settings, then the Two-Factor Authentication section. Each method shows either Not Set Up or Enrolled.
  3. Next to Authenticator App, click Set Up.
  4. Scan the QR code with your authenticator app. If the camera will not scan it, type the code shown beside Manual key: into the app instead.
  5. The app now shows a six-digit code. Type it into Enter the 6-digit code shown in your app to confirm: and click Verify & Enable.
Account Security Settings, showing the Two-Factor Authentication panel with Authenticator App and SMS Text Message, each with a Set Up button.

The method then reads Enrolled. To use a text message instead, click Set Up beside SMS Text Message, enter the number under Mobile Phone Number - Include country code (e.g. +1 for US) - and click Send Verification Code, then enter the code that arrives. If it does not arrive, Change number / Resend will send it again or let you correct the number.

To stop using a method, click Remove beside it.

Require it across the practice

Setting up MFA is voluntary until an administrator requires it. There are two ways to do that, both on the Admin page in the Users section.

The Require MFA for All Users switch at the top of the Users list on the Admin page.

Requiring MFA does not enrol anyone. It means that the next time that person signs in, they must finish setting up a method before they can carry on. Turn it on when the people affected are at work and able to reach their phones, not last thing on a Friday.

Read the Users list at a glance

The MFA column on the Users list shows where each person stands. Hover an icon to read it:

When someone loses their phone

A new or wiped phone no longer holds the enrolment, and the old codes are gone. An administrator clears it so the user can start again: open Edit User, and under MFA Status: beside Authenticator App: click Reset TOTP. The user is then Not enrolled and sets the app up again from their own Account page.

Only an administrator can do this, and it is deliberate - being able to clear your own second factor would defeat the point of having one.

Back to Articles