Multi-factor authentication (MFA) adds a second step to signing in: after entering a password, a staff member also confirms a code from an authenticator app, a text message, or a backup code. CoolFocus 5 supports MFA at two levels — each person can turn it on for their own login, and an administrator can require it for everyone entering the organization.
This article covers staff logins to CoolFocus 5. The Client Portal's two-step verification for clients is a separate setting.
Any staff member can add a second factor to their own account, whether or not the organization requires it.
Select your profile picture in the top right, then Manage account.
Open the Security tab and add a second factor — an authenticator app, text message codes, or backup codes.
Save the backup codes you are given. They are how you sign in if you lose your phone or your authenticator app.
A passkey does not count as a second factor. A passkey replaces your password rather than adding a step after it, so if your organization requires MFA you still need an authenticator app, text message codes, or backup codes.
This is enough to protect your own login even if your organization does not require MFA for everyone.
Only administrators can see or change this setting.
Go to Settings > Security > Multi-factor authentication.
Turn on Require multi-factor authentication.
Select Save.
You need a second factor on your own account first. Until you do, the toggle stays switched off and the page explains why, with a button that opens your account security. This is what stops an administrator from locking themselves out of their own organization the moment they save.
Once the requirement is on:
Staff who already have MFA are not interrupted.
Staff without a second factor are held at a Multi-factor authentication required screen before they reach the organization. It has Open account security to set MFA up, and Check again to continue once setup is finished. Enrollment is not picked up on its own — select Check again.
The requirement applies to this organization only. Someone who works in more than one organization is stopped only at the ones that require MFA.
If someone removes their second factor later, they are stopped the next time they enter the organization until they set it up again.
Turning the requirement back off removes the screen for everyone. Anyone who already enrolled keeps their own MFA.
An administrator who is caught by the requirement — for example after losing the phone holding their authenticator app — sees an extra option on the blocking screen: Turn off the MFA requirement. It switches the requirement off for the whole organization so they can get back in, and it can be turned on again once they have re-enrolled.
Staff who are not administrators do not see this option. They need to finish MFA setup, or ask an administrator.
If you are an administrator and the requirement will not save, one of these is usually why:
You do not have a second factor yet. The toggle stays off and the page shows an amber note asking you to set up MFA on your own account first. Use Open account security, finish setup, then return to the page.
Your MFA setup could not be confirmed. If CoolFocus cannot reach the sign-in service it will not enable the requirement, and saving shows a message asking you to try again. Wait a moment and save again.
You are not an administrator. Only administrators can open or change this setting. Check Settings > Security > Users, or ask someone who is.
No. CoolFocus 5 uses its own sign-in system, separate from CoolFocus 3. MFA settings, authenticator app pairings, and backup codes from CoolFocus 3 do not transfer during an upgrade.
Each staff member sets up MFA again in CoolFocus 5, either on their own or because your organization turned on the org-wide requirement above.