Customers using Single Sign-On (SSO) to log on will not be required to use 2FA. If users choose to bypass SSO and log on with an Envoy password, 2FA will then be required.
Overview
Envoy uses email and app-based two-factor authentication (2FA, also called 'Multi-factor authentication') for improved security. This adds an extra layer of security to protect your account and data. To access your Envoy account, you will need to enter a unique, one-time PIN in addition to your password. This authentication is valid for 30 days.
2FA is a simple but powerful way to keep your information safe and reduce the risk of unauthorized access.
This is an automatic change that came into effect on December 16, 2024. It applies to all Envoy user accounts, regardless of subscription, product, and admin role. No further action is required at this time.
Troubleshooting 2FA and FAQ
How does 2FA work?
The first time you log in to Envoy on a new device, a 6-digit One-Time PIN (OTP) will be sent to the email address associated with your Envoy account. If you are logged into the Envoy mobile app, you will also be sent a push notification.
You will be prompted to input this PIN to proceed with login. Once you have input the correct PIN, your login will proceed as normal.
How does 2FA work with SSO?
If your Envoy account uses SSO (via Okta or Entra, for example), employees would not be required to use Envoy's 2FA system in addition to SSO. If SSO is not set to be required, users will be able to log in via password and would, therefore, need to complete Envoy's 2FA.
Learn more about setting up SAML.
Will this affect Visitor sign-in?
No. 2FA is applied to employee and admin accounts that log in to your company's Envoy web dashboard. Visitor sign-in on the iPad kiosk will NOT require 2FA.
Does 2FA work with Envoy mobile logins?
Logging in to Envoy mobile is completed via "Magic link" or SSO (if enabled). Envoy mobile does not support a standard password login and, therefore, does not require 2FA.
An OTP will be sent to Envoy mobile if you have the app downloaded, but the app itself does not rely on the same 2FA process the dashboard uses.
Will I be required to use a PIN each time I log in?
You will have the option to authorize only every 30 days while on the same device. This is not recommended for users of shared devices.
✨"Incognito" or private browsing usually doesn't save cookies - you might need to re-authorize every login if you prefer to use a private browser✨
Not receiving your authorization code email?
Ensure the email address you enter into Envoy is correct.
Search for the subject line "Your Envoy confirmation code."
Check your spam/junk folders to see if your email provider is filtering our emails.
Still don't see the code email? Contact our support team via live chat or [email protected].
Not receiving your authorization code push notification?
Ensure you're logged into Envoy mobile with the same email address you're attempting to use for the Envoy web dashboard.
Check the version of your app. Envoy mobile identity push notifications are available on v.4.90.0 and up.
You do not need to have host push notifications enabled to receive OTP as a push notification.
PIN Expiration
2FA One-Time PINs expire 5 minutes after they are sent to you. If you are unable to input the PIN before it expires, you can request a new PIN to be sent.
Entering the Incorrect PIN
If you fail to enter the correct PIN 5 times, you will be required to request a new PIN.
What if we use a shared login to access Envoy?
We highly discourage relying on a shared login due to the increased risk of unauthorized access and compliance violations. It is best practice for every user to have a unique login, meaning that every employee should have their own profile in the employee directory. If you do use a shared login, users must be able to access that inbox to retrieve the PIN within 5 minutes.
Envoy Visitors basic and standard plans allow for a maximum of 50 employees in the directory. Envoy Workplace allows for unlimited employees and is billed on active users. Learn more about our pricing.