Skip to main content

Two-Factor Authentication By Staff

Neos supports Two-Factor Authentication (2FA) to give your firm an additional layer of security. Two-Factor Authentication can be enabled by administrators for all users in Firm Preferences or for individual users in Staff Profiles. An authorization code will be sent to a user's email or mobile phone number from their Staff Profile. Once successful, the user can be remembered by Neos for 30 days.

If your firm uses the Neos add-ins for QuickBooks, Word and/or Outlook, each Staff must update to the latest add-in versions before Two-Factor Authentication is turned on to continue accessing these integrations uninterrupted.

NOTE: You must have full administrator permissions (Enable, Add, Edit, and Delete) to General > Firm Preferences and Directory > Staff Directory to enable or disable 2FA in Staff Profiles.

Two-Factor Authentication can be turned on for individual users in Staff Profiles. Users must have their email and/or mobile phone number saved in order to enable 2FA.

To enable Two-Factor Authentication for individual staff:

  1. Click the Settings button on the left navigation pane and select Staff Profiles.

  2. From the list, select the desired Staff to display their Staff Profile tab.

  3. Ensure the Staff's Email Address and/or Mobile phone number has been entered and saved.

  4. Scroll to the User Account Details section and select Enable Two-Factor Authentication.

    NOTE: If the staff does not have an email address OR mobile phone number entered in their Staff Profile, 2FA cannot be enabled.

    In addition, if 2FA has been enabled globally in Firm Preferences and a Staff does not have an email address OR mobile phone number in their Staff Profile, the Staff Information Tab cannot be saved unless the Mobile or Email field is entered/validated.

  5. When Two-Factor Authentication is turned on, a success message will display.

    NOTE: The Staff Mobile number cannot be deleted when Two-Factor Authentication has been enabled and their Email does not exist.

  6. On the user's next Neos login, they will receive a Two-Factor Authentication message with a code sent to either their Mobile number or Email, as saved in their Staff Profile. Simply closing and reopening your browser will not prompt 2FA if you are currently logged in to Neos.

NOTE: If 2FA has been turned on globally in Firm Preferences and a Staff does not have a Mobile number or Email entered in their Staff Profile, they will be prompted at next login to enter their mobile number. Once entered, click the Send Code button to receive an authorization code. Neos will save the Staff's mobile number in the Mobile field on their Staff Profile.

  • If the Staff only has a Mobile number saved, the authentication code will be sent to their Mobile device.

  • If the Staff only has their Email saved/activated, the authentication code will be sent to their linked Email.

  • If the Staff has an Email AND Mobile number saved to their Staff Profile, they can choose where the authentication code will be sent. Click the Send Code button.

NOTE: Only the last four digits of the Staff's 10-digit number and first two characters from the username of their email will be visible for security purposes.

7. The Staff will receive a one-time six-digit authentication code to their mobile device or email.

8. Enter the six-digit code into the Verification Code field. Select the Do not ask again for 30 days check box below the authentication code if you wish Neos to remember you on this browser for 30 days. If a new browser is used, you will be prompted with the Two-Factor Authentication process again. Click the Login button to log in to Neos.

NOTE: Authentication codes are only valid for one hour. If an expired code is entered, you will receive the following error messages when the Login button is clicked.

9. If you have misplaced the authentication code or if the current code has expired, click Request another code below the Login button to receive a new one-time-use authentication code.

NOTE: If the wrong 2FA code is entered 5 times within 5 minutes, that user will be temporarily locked out of Neos. Each subsequent invalid code will result in a longer lockout time. The user will receive a message asking them to try again in 5 minutes.

10. When the correct code is entered, you will be logged into Neos.

Did this answer your question?