Two-Factor Authentication
Enforce 2FA for any or all user roles — TOTP, SMS OTP, or email OTP — with device trust management and instant revocation.
Two-Factor Authentication adds a critical second layer of verification to every login — so a compromised password alone is never enough to access the platform. YoApp supports TOTP authenticator apps, SMS OTP, and email OTP — enforceable per role or per individual user. Device trust lets users register known devices to streamline repeat logins, while instant revocation ensures a lost or stolen device can be locked out immediately.
Everything you need, nothing you don't
TOTP Authenticator Support
Users enrol a TOTP authenticator app (Google Authenticator, Microsoft Authenticator, Authy) by scanning a QR code. A 6-digit time-based code is required at every login.
SMS OTP
Users who cannot use an authenticator app receive a one-time password by SMS — generated and valid for 5 minutes — as a second factor at login.
Email OTP
Email-based OTP as a third option — useful for users without a mobile number on the platform, or as a fallback when SMS delivery fails.
Per-Role Enforcement
Configure which roles require 2FA — enforce it for all admin roles immediately, roll it out to branch staff progressively. Users not yet enrolled are prompted to set up 2FA at next login.
Device Trust Registration
Users can register trusted devices — their own laptop or phone — to skip the 2FA step on future logins from that device for a configurable trust period (e.g. 30 days).
Instant Device Revocation
Revoke trust for any registered device instantly from the admin panel — critical when an employee's device is lost, stolen, or when they leave the organisation.
Re-Authentication for High-Risk Actions
Force re-authentication with a second factor before high-risk actions — bulk payment execution, role assignment, write-off approval — regardless of the user's active session state.
2FA Compliance Reporting
Report showing 2FA enrolment status across all users — enrolled, pending, and exempt — with last-verified date per user for compliance monitoring.
Built for your team
Enforce strong authentication across your entire user base — protecting against the most common attack vector (credential theft) with minimal friction for legitimate users.
Ensure that every user with access to sensitive financial functions — approvals, disbursements, write-offs — is protected by a second authentication factor.
Protect your account from unauthorised access even if your password is compromised — with a simple, industry-standard second factor that takes seconds to complete.
Ready to activate Two-Factor Authentication?
Sign up free and configure Two-Factor Authentication in minutes — or book a demo and we'll walk you through it live.