If an Organisation chooses to enforce 2FA for a higher level of security in RePro, as a user you will need to follow these steps to enable 2FA on your account.
Before you start you will need an authentication app like Google Authenticator or Authy.
Steps to Authorise your login with 2FA:
Click the link in the Accept Invitation in the email sent to you by RePro
Your browser will open and you will see a form requesting you information
Fill in the requested details - Name, Telephone number, a password of your choice
Click: Next
Important Note: 2FA requires a valid mobile phone number on your account – we send you a code by SMS to the number on your account, and you will need to enter it in order to complete the 2FA process.
If 2FA is enforced by an administrator on your account you will see this - click: GOTO 2FA SETTINGS
Click: ENABLE 2FA
You will be asked to verify the phone number you entered - if it's correct, click SUBMIT
You will receive a 6 digit code via SMS to the number you gave - enter this in to the the "SMS Verify Code" box
You will now need to set up your authenticator app on your phone.
Open your authenticator app and create a new 2FA profile by selecting the QR code method.
When the camera view opens, point it at the QR code on the screen of the RePro Stream browser page.
Your authenticator app should create a brand new RePro Stream authentication profile and it will display 6 numbers.
Enter these 6 numbers into the RePro Stream browser to confirm your authentication code.
Once you submit you will now always need to use 2FA as well as your regular password to sign in.
If you lose your authenticator app
If you lose your authenticator app or device, contact RePro Support from the email address on the account to recover access. Self-service and SMS recovery are not available.
Once the account is confirmed, Support can clear the existing 2FA profile so you can set up a new one.
Keep a second way in. Most authenticator apps can back up or transfer profiles between devices. Set that up when you enable 2FA, not after you have lost the phone.
Enforcing 2FA across an Organisation
An Organisation can require 2FA of everyone who signs in to it. The setting lives in Organisation Settings, under Security.
Enforcing 2FA at the Organisation level already covers every Project in that Organisation. There is no need to set it on each Project as well. Project-level enforcement is there for the case where the Organisation-level setting is off and a single Project needs to require 2FA on its own.
Once enforcement is on, users who have not enabled 2FA cannot access the Organisation and are not prompted to set it up. They can still sign in, and they keep access to any other organisation they belong to, but everything in this one is closed to them until they enable 2FA. Because that needs a verified phone number, tell people to do both before you switch enforcement on rather than after.
Guest links and enforced 2FA
A guest link grants viewing access to whoever holds it. Guest links are exempt from the 2FA requirement.
If your Organisation enforces 2FA because every viewer must authenticate that way, disable guest links for that Organisation as well – enforcement alone will not cover them. Talk to RePro Support about restricting guest links.






