---
title: "Account Security"
description: "Harden your own sign-in: authenticator-app two-factor codes backed by recovery codes, a review of your active browser sessions, and linked Google, Microsoft, or Slack sign-in, all managed from your profile."
category: "Workspace & security"
updated: 2026-08-27
canonical: https://approvethis.com/docs/manuals/account-security
---

# Account Security

Two-factor authentication on ApproveThis is set up from your own Profile page, under the Security tab, and it starts with an enrollment screen that pairs your account with an authenticator app. This section covers that first half: proving it's you with your password and getting the QR code and setup key on screen. Two-factor here is authenticator-app codes only — there is no SMS, email-code, passkey, or hardware-key option — and it's a per-user choice, so an administrator turns it on for their own sign-in, not for the workspace. You'll need an account that has a password set; accounts created purely through Google, Microsoft, or Slack sign-in don't show the Security tab at all.

**Who this is for:** an Administrator.

> **Prerequisite:** Sign in as an Administrator.

> **Getting here:** Open the avatar menu in the top navigation and choose Profile.


## On the Security tab, click 'Enable' under Two-Factor Authentication and confirm your password — the QR code and setup key appear, ready to scan with your authenticator app

Getting the QR code on screen is the gate to everything else in two-factor setup: nothing is protected yet, because 2FA only becomes active once you enter the 6-digit code from your authenticator app and confirm it. Worth knowing before you start: once 2FA is live on your account, emailed approval and view links stop logging you in automatically and send you to the normal login page instead.

1. Sign in as the administrator whose sign-in you're hardening.
2. Click **Security** to open the security settings for your profile.

   ![Click Security to open the security settings for your profile.](https://approvethis.com/docs-assets/manuals/account-security/screenshots/account-security-s1-01.png)

3. Under the Two-Factor Authentication card, click **Enable** to begin enrollment.

   ![Under the Two-Factor Authentication card, click Enable to begin enrollment.](https://approvethis.com/docs-assets/manuals/account-security/screenshots/account-security-s1-02.png)

4. Type your own account password into **Password** — the example uses `docs-password`.

   ![Type your own account password into Password — the example uses docs-password.](https://approvethis.com/docs-assets/manuals/account-security/screenshots/account-security-s1-03.png)

5. Click **Confirm** to verify the password and reveal the enrollment details.

   ![Click Confirm to verify the password and reveal the enrollment details.](https://approvethis.com/docs-assets/manuals/account-security/screenshots/account-security-s1-04.png)


> **Success cue:** Enrollment is open once the QR code appears beneath **Scan with your authenticator app**, alongside the manual setup key.

> **What happens next:** Finish on your phone: scan the QR code (or type the setup key) in your authenticator app, enter the 6-digit code it shows, and click Confirm — two-factor is not active until that code is confirmed. Your recovery codes then appear; store them safely. The same profile page carries your Connected Accounts (Google, Slack, Microsoft sign-in), your active browser Sessions, and account deletion. Note that enabling two-factor also turns off auto-login on emailed approval links for your account — you'll sign in normally instead.

