Skip to main content

Multi-Factor Authentication (MFA) in Heidi

Setting Up, Troubleshooting, and Disabling MFA

Multi-Factor Authentication (MFA) adds an extra layer of security to your Heidi account, helping to protect your data. MFA is mandatory in certain regions such as the UK and EU (for username and password accounts). This does not include accounts that use Single-Sign-On (SSO) or Social Sign-In (e.g. Google, Apple). While it is optional for some account types and regions, we highly recommend enabling it for enhanced security.


Enabling MFA

You can enable MFA at any time through the Heidi platform (mobile app, desktop app, or web browser). We recommend setting up an authenticator app such as Google Authenticator that can be used for MFA. This can be downloaded from your relevant app store on your mobile.

  1. Go to your account settings:

    1. On the Mobile app:
      Check within Settings that your app is version v3.7+.
      Then go to: Settings > Multi-Factor Authentication (MFA). This will direct you to log in on web.

    2. On the the Desktop app or Web: Your name > Settings > Account > Login Details > Enable MFA.

  2. You’ll see two options: Set up later or Log out and set up now.

  3. Click Log out and set up now

  4. Sign back in using your username and password.

  5. You will be prompted to use an authenticator app to set up MFA.

    1. If you have an authenticator app, open the app and scan the QR code to receive a one-time password. If you are on mobile, copy the code presented to you on screen into your authenticator app to receive your one-time password.

    2. If you do not have an authenticator app, we recommend downloading one from your relevant app store.

  6. If you’d prefer a different method to set up MFA, select Try another method.

  7. You can select:

    1. Google Authenticator or similar to set up a different authenticator app.

    2. SMS if you’d prefer to not use an authenticator app.


MFA Setup Options

1. Authenticator App (Recommended)

For the most secure login experience, we recommend using an authenticator app such as Google Authenticator, Microsoft Authenticator, or Duo Mobile.

  1. Select Authenticator app as your MFA method.

  2. A QR code will appear on your screen.

  3. Open your Authenticator app and choose the option to Add a new account using a QR code.

  4. Scan the QR code with your mobile camera, name your Heidi account, and save it.

  5. Your Authenticator app will now generate a one-time secure code - enter this code into Heidi and click Continue.

  6. Next time you log in, open your Authenticator app to retrieve a one-time code, then enter it into Heidi when prompted to sign in.

2. SMS Authentication

If you cannot see SMS as an option, let us know so we can reset your MFA for you.

  1. Select SMS as your MFA method.

  2. Enter your country code and mobile number, then click Continue.

  3. You’ll receive a security code via SMS.

  4. Enter the code into the Heidi code box and click Verify.

  5. You can confirm that MFA is enabled by going to Settings > Account > Login Details - you should see a green Enabled symbol next to MFA.

  6. Next time you log in, Heidi will send a security code to your mobile via SMS. Simply enter the code when prompted to sign in.

3. Email Authentication

You will need to choose either an authenticator app or SMS as the initial authentication method during setup. Once MFA is set up, log in for the first time with it enabled. You can then select email as your verification method for future logins.

  1. Login after you have set up MFA using an authenticator app or SMS.

  2. Select Try another method.

  3. Select Email as your MFA method.

  4. Enter the email address you want to link to your Heidi account.

  5. Heidi will send a secure code to your email. Check your spam folder.

  6. Enter the code into the Heidi code box and click Verify.

  7. Next time you log in, you’ll receive a security code via email. Simply enter the code when prompted to sign in.


Disabling MFA

If you need to disable MFA, it can be toggled off within your settings. However, disabling MFA is not possible for regions where MFA is mandatory, such as the UK and EU for username and password accounts.

  1. Go to Settings > Account > Login Details > Disable MFA.

  2. You should now see a red Not enabled symbol next to MFA.


Troubleshooting

First, a couple of general troubleshooting tips:

  • Clear your browser cache to resolve temporary glitches that may prevent MFA from working correctly.

  • You need a stable internet connection to receive MFA codes.

I have lost MFA access because I changed my device

  1. Let us know that you need to reset your MFA.

  2. You'll need to verify your identity during this process.

  3. Once reset, log back in and set up a new authentication method.

I didn’t receive an SMS code

  1. Tap Resend code and wait a few moments before trying again.

  2. Some mobile providers may block SMS codes as spam. If this happens consistently, you may need to switch to a different method.

  3. For the most reliable experience, consider switching to an authenticator app - it's faster and doesn't depend on mobile network delivery.

I didn’t receive an email code

  1. Check your spam or junk folder - MFA emails can be filtered by some providers.

  2. Try a different platform (desktop app or a different browser) and resend the code.

  3. Clear your browser cache and try again.

  4. If your organisation manages your email, check with your IT team in case the email is being blocked at a network level.

  5. If the issue persists, you may need to switch to a different method such as an authenticator app instead.

I am having problems with my authenticator app

  1. Each authenticator app is managed independently, so you'll need to contact the support team for the app you're using - for example, Google Authenticator or Microsoft Authenticator support.

I don’t see the option to use SMS as my authentication method

  1. If you are not presented with SMS as an option when updating your authenticator method, let us know so we can reset your MFA settings for you.

My authenticator app shows multiple codes for Heidi

  1. If your authenticator app shows more than one code for Heidi, typically, the new code generator will be at the bottom of the list. This is the one you should use when logging into Heidi.

  2. We recommend you remove the previous code generator.

I can't enable MFA from my mobile app

  1. If you are having issues with enabling MFA from your mobile app, make sure your mobile app is up-to-date from v3.7+.

I can’t set up MFA for social sign-in (e.g. Google or Apple)

  1. If you log in to Heidi using Google or Apple, MFA is not required (even in regions where it's mandatory such as the UK and EU).

  2. The Enable MFA option will be greyed out in your settings.

My organisation uses SSO, should I enable MFA?

  1. If your organisation uses Single Sign-On (SSO), such as Okta or Azure, entering your username on Heidi’s login page should redirect you to your SSO provider sign-in page.

  2. MFA will be handled by your SSO provider, if you have it enabled. You do not need to set up MFA with Heidi. The Enable MFA option within your Heidi settings will still be available but it will have no effect.

Did this answer your question?