# How to enable two-factor authentication at the Hideez Enterprise Server?

{% hint style="info" %}
This guide explains how to enable two-factor OTP (One-Time Password) authentication for accessing the Hideez Enterprise Server (HES) web interface. To enable OTP for other websites, you must configure the appropriate settings on those sites.
{% endhint %}

***

### **Enabling 2FA for Admin Accounts**

#### **Step 1:**

In the top-right corner of the window, click on the **profile icon** and select **Profile** from the drop-down list.

<figure><img src="https://1669663611-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FRdTysrljwe610dPFG7tE%2Fuploads%2FgVwdYz8TPlwexg2RAVnD%2Fimage.png?alt=media&#x26;token=fd0ebefc-f798-479c-8fa4-a29eb1db0502" alt=""><figcaption></figcaption></figure>

#### **Step 2:**

In the Profile section, go to **One-Time Password** and click on the **Add OTP App** button.

<figure><img src="https://content.gitbook.com/content/RdTysrljwe610dPFG7tE/blobs/1YBYY0J04gT87R8VFVBN/image.png" alt=""><figcaption></figcaption></figure>

#### **Step 3:**

Follow the on-screen instructions to set up 2FA.

<div><figure><img src="https://1669663611-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FRdTysrljwe610dPFG7tE%2Fuploads%2FcrIVPNtl3r0p2NqpKbuV%2FScreenshot_2.png?alt=media&#x26;token=87016aa2-4129-4dd9-93f7-35c4f542a31b" alt="" width="563"><figcaption></figcaption></figure> <figure><img src="https://1669663611-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FRdTysrljwe610dPFG7tE%2Fuploads%2FgtiBp3hzNS8Pl0jcU9cP%2Fphoto_2024-10-01_16-33-58.jpg?alt=media&#x26;token=706ee512-355d-424b-8937-3a262ded1f7a" alt="" width="371"><figcaption></figcaption></figure></div>

You can use [**Hideez Authenticator**](https://enterprise.hideez.com/hideez-authenticator-app) as the OTP generation application.

#### **Step 4:**

After successfully enabling two-factor authentication, you will be prompted to save your **recovery codes**. You will receive 10 recovery codes, each consisting of 8 characters. These can be used in case you are unable to generate an OTP code.

{% hint style="warning" %}
**Important:** Save these recovery codes in a secure place.
{% endhint %}

Two-factor authentication is now configured, and you can use it with your OTP application.

***

### **Using Hideez Key for OTP Generation**

If you want to use the [**Hideez Key** to generate OTPs](https://enterprise.hideez.com/use-cases/hideez-key/password-manager-and-otp-generator#enabling-otp-input-for-your-accounts), when creating your admin account, enter the **Secret Key** provided during the OTP setup in the corresponding field.

![](https://content.gitbook.com/content/RdTysrljwe610dPFG7tE/blobs/jNzPEIPLz5hCsDikimte/image.png)

The **Secret Key** is a 32-character value provided in **Step 3**.

\
[Learn more about creating accounts via Hideez Client](https://enterprise.hideez.com/hideez-client-app/account-management/account-creation). \
[Learn more about creating accounts on HES](https://enterprise.hideez.com/hideez-enterprise-server/accounts/how-to-work-with-personal-employee-accounts). \
[How to enter credentials with the Hideez key](https://enterprise.hideez.com/hideez-key-enterprise-edition/how-to-enter-credentials-with-hideez-key).

***

### **Disabling 2FA on HES**

#### **Step 1:**<br>

Go to the **Profile** tab and locate the **One-Time Password** section. Click **Disable 2FA**.

![](https://content.gitbook.com/content/RdTysrljwe610dPFG7tE/blobs/SwQogfcfvZyouIH9Xjc8/2fa%20on%20hes3.jpg)

#### **Step 2:**<br>

Confirm the action to disable two-factor authentication.

{% hint style="info" %}
Two-factor authentication is now disabled, but you can enable it again at any time.
{% endhint %}

***

### **Resetting Recovery Codes**

When you disable and then re-enable 2FA, your recovery codes will be reset.

{% hint style="info" %}
**Note:** If you reset the OTP app without disabling 2FA, the recovery codes will **not** be reset.
{% endhint %}

***

### **Logging In with a Recovery Code**

If you cannot enter the OTP code during login, you can use a recovery code.

#### **Step 1:**<br>

Enter your login and password.

#### **Step 2:**<br>

Click on the **One-Time Password** button.

#### **Step 3:**<br>

Click **Log in with a recovery code**.

<figure><img src="https://1669663611-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FRdTysrljwe610dPFG7tE%2Fuploads%2FxqpVmSfXZPH9WXTDKnpN%2FScreenshot_4.png?alt=media&#x26;token=a85b3caa-267a-41f2-8370-00cf88cfdd3a" alt="" width="265"><figcaption></figcaption></figure>

#### **Step 4:**<br>

Enter one of your previously saved recovery codes and click **Login**.

<figure><img src="https://1669663611-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FRdTysrljwe610dPFG7tE%2Fuploads%2FzF7gWSXInfHRBUpbw5Ui%2FScreenshot_6.png?alt=media&#x26;token=b3b1e78e-2f45-4380-b1b7-191a65da6830" alt="" width="262"><figcaption></figcaption></figure>

***

{% hint style="info" %}
This completes the setup and usage guide for two-factor authentication on Hideez Enterprise Server.
{% endhint %}
