Knowledgebase Article
Category: Configuration | Module: OfficePro | Created: 9/5/2026 | Last Updated: 9/5/2026
Multi-factor authentication (MFA) asks for a second piece of proof after the password, so a stolen or guessed password is not enough on its own to reach patient records. OfficePro offers two methods, and each user sets up their own.
A user can set up both. If both are enrolled, the authenticator app is offered first and the text message is available as a fallback.

The method then reads Enrolled. To use a text message instead, click Set Up beside SMS Text Message, enter the number under Mobile Phone Number - Include country code (e.g. +1 for US) - and click Send Verification Code, then enter the code that arrives. If it does not arrive, Change number / Resend will send it again or let you correct the number.
To stop using a method, click Remove beside it.
Setting up MFA is voluntary until an administrator requires it. There are two ways to do that, both on the Admin page in the Users section.

Requiring MFA does not enrol anyone. It means that the next time that person signs in, they must finish setting up a method before they can carry on. Turn it on when the people affected are at work and able to reach their phones, not last thing on a Friday.
The MFA column on the Users list shows where each person stands. Hover an icon to read it:
A new or wiped phone no longer holds the enrolment, and the old codes are gone. An administrator clears it so the user can start again: open Edit User, and under MFA Status: beside Authenticator App: click Reset TOTP. The user is then Not enrolled and sets the app up again from their own Account page.
Only an administrator can do this, and it is deliberate - being able to clear your own second factor would defeat the point of having one.