The Credentials Settings page is your security command center, allowing you to manage all aspects of your account authentication and access controls.
Overview
Account security is crucial for protecting your organization's data and maintaining user privacy. The Credentials Settings page provides tools to:
- Update your login email
- Change your password
- Enable multi-factor authentication
- Manage security settings
Email Management
Your email address serves as your primary login credential and communication channel.
Updating Your Email
To change your account email:
- Enter your new email address
- Click "Update Email"
- Check your new email for a verification message
- Click the verification link to confirm the change
- Your email will be updated once verified
Important Notes
- You'll need access to the new email address to complete verification
- Your old email will receive a notification of the change
- You'll use the new email for all future logins
- Any pending password reset links will be invalidated
Password Management
Regular password updates help maintain account security.
Changing Your Password
To update your password:
- Enter your current password
- Create a new password meeting these requirements:
- Minimum 8 characters
- Mix of uppercase and lowercase letters
- At least one number
- At least one special character
- Re-enter the new password to confirm
- Click "Update Password"
Password Best Practices
- Use unique passwords for each service
- Avoid common words or personal information
- Consider using a password manager
- Update passwords regularly
- Never share your password
Multi-Factor Authentication (MFA)
MFA provides an additional security layer beyond passwords, significantly reducing unauthorized access risks.
Understanding MFA
Multi-factor authentication requires two or more verification methods:
- Something you know (password)
- Something you have (phone or authenticator app)
- Something you are (biometric data)
Setting Up MFA
To enable multi-factor authentication:
- Click "Set Up MFA" in the Multi-Factor Authentication section
- Choose your preferred method:
Authenticator App (Recommended)
- Download an authenticator app (Google Authenticator, Authy, Microsoft Authenticator)
- Scan the QR code displayed
- Enter the 6-digit code from your app
- Save your backup codes securely
SMS Authentication
- Enter your mobile phone number
- Verify with the code sent via text
- Keep your phone number updated
- Complete the setup process
- Test your MFA to ensure it works
Managing MFA Factors
Once MFA is enabled, you can:
View Active Factors
See all enabled authentication methods and when they were added
Add Backup Methods
Set up alternative authentication options:
- Additional phone numbers
- Backup authenticator apps
- Hardware security keys
Remove Factors
Disable specific authentication methods when:
- Changing phones
- Switching authenticator apps
- Updating security preferences
Backup Codes
When you enable MFA, you'll receive backup codes:
- Save these codes in a secure location
- Each code works once for emergency access
- Generate new codes if you run out
- Treat them like passwords - keep them private
Using MFA
With MFA enabled, logging in requires:
- Enter your email and password
- When prompted, provide your second factor:
- 6-digit code from authenticator app
- Code sent via SMS
- Backup code (for emergencies)
- Optionally check "Remember this device" for trusted computers
Troubleshooting MFA
Lost Phone or Authenticator
If you can't access your primary MFA method:
- Use a backup code to log in
- Access Credentials Settings
- Remove the lost factor
- Set up a new authentication method
Codes Not Working
If your authenticator codes are rejected:
- Ensure your device's time is synchronized
- Try the next code if one just expired
- Use a backup code if needed
- Contact support for assistance
Account Recovery
If you're completely locked out:
- Click "Can't access your account?" on login
- Follow the recovery process
- Verify your identity
- Work with your administrator to regain access
Security Recommendations
Strong Security Practices
- Enable MFA - Always use multi-factor authentication
- Regular Updates - Change passwords periodically
- Unique Passwords - Don't reuse passwords across services
- Secure Storage - Use a password manager
- Stay Alert - Report suspicious activity immediately
Warning Signs
Watch for these security concerns:
- Unexpected login notifications
- Password change emails you didn't request
- Unusual account activity
- MFA prompts you didn't trigger
Report any suspicious activity to your administrator immediately.
Account Recovery
If you lose access to your account:
- Self-Recovery - Use password reset if you have email access
- MFA Recovery - Use backup codes or contact your admin
- Administrator Help - Your organization admin can assist with recovery
- Identity Verification - Be prepared to verify your identity
Support
For security-related assistance:
- Review this documentation first
- Contact your organization administrator
- For urgent security issues, contact support immediately
- Never share credentials in support communications