Account security
How to enable two-step authentication, what to do if you lose access to 2FA, how to reset your password, and how to unlock your account.
The rules on this page apply to any account that authenticates with email and password, whatever your role — administrator or employee.
If you don't see the 2FA option in your profile
Either your organization uses SSO authentication — in which case the second factor is managed by the organization, not by the platform — or 2FA is not available on the installation you are using. Ask your organization's representative.
Two-step authentication (2FA)
2FA adds a verification code on top of your email and password. You enable it individually, from My Account > Profile, the Two-step authentication section.
Which method to choose
| Authenticator app | Code by email | |
|---|---|---|
| How you get the code | generated locally by the app | sent to the account address, at every sign-in |
| You need a phone / app | yes | no |
| You need email access at every sign-in | no | yes |
| Works without internet on the device | yes | no |
Use the authenticator app
This is the recommended method: the code is generated on your device, does not depend on email delivery, and cannot be intercepted in transit. It works with any TOTP-compatible app — Google Authenticator, Microsoft Authenticator, and others.
Choose the email code only if you don't have a phone on which you can install an authenticator app. In that case, the security of your account depends on the security of your mailbox: if your email is compromised, the second factor is compromised.
The method cannot be changed directly. If you want to switch from one method to the other, disable 2FA and re-enable it with the method you want.
How to enable 2FA
- Go to My Account > Profile, the Two-step authentication section.
- Choose the method from the Choose the authentication method list.
- Press Enable. If you chose the email method, you immediately receive a confirmation code.
- Confirm the method:
- Authenticator app — scan the QR code displayed with the app, then enter the 6-digit code generated by the app;
- Email — enter the 6-digit code received by email.
- Press Confirm.
2FA becomes active only after the code has been confirmed correctly. If you enter a wrong code, activation does not complete and you can try again — until confirmation, authentication remains unchanged.
After activation, the section shows you the active method and a Disable button.
The QR code is confidential
Do not photograph it for others, do not send it by email, and do not keep it in places accessible to other people. Anyone who scans it can generate valid codes for your account.
How to sign in when 2FA is active
- Enter your email and password on the authentication page.
- If the details are correct, you reach the 2FA verification page. With the email method, a new code is sent at this moment, at every sign-in.
- Enter the 6-digit code.
A code that has already been used cannot be reused. With the email method, if you request a new code by restarting the sign-in, use the most recent code received.
Email delivery delays
The code remains valid for approximately 3 minutes from generation, precisely to cover delivery time. If the email takes longer than that, the code you receive will no longer be accepted: restart the sign-in to receive a new code, rather than repeatedly trying an expired one — failed attempts count toward account lockout.
How to disable 2FA
As long as you can still sign in, disabling is self-service: My Account > Profile > Disable.
On deactivation, your account's 2FA configuration is permanently deleted. If you re-enable it later, you must scan a new QR code — the previous one is no longer valid.
You receive an email on every deactivation
The platform automatically sends a notification to the account address, with the subject „Autentificare în doi pași dezactivată” (“Two-step authentication disabled”), both when you disable 2FA yourself and when it is disabled by the support team.
If you receive this notification without having requested the deactivation, contact the support team immediately — your account may be compromised.
I lost access to my 2FA method
Lost phone, reinstalled app, lost access to the mailbox — the platform does not use backup codes, so the only recovery path is deactivation of 2FA by the support team.
The reset is performed only on the basis of two independent requests: your request and the confirmation of your organization's Super User. Neither is sufficient on its own, and the two must reach support through separate channels.
- You submit the request, preferably from the email address registered on the account.
- Support separately requests confirmation from the company, which verifies the requester's identity.
- Support disables 2FA, and you automatically receive the notification email.
- You sign in with email and password only, and re-enable 2FA yourself, through a new enrollment.
The previous configuration is not recovered. The support team can only disable 2FA — it cannot rebuild or transfer your method.
If you have lost access to the email address itself, see I lost access to my email address.
Password
Your password must be at least 8 characters (maximum 128) and is case-sensitive. The email address is not case-sensitive, and leading and trailing spaces are ignored.
Choose a long password used exclusively for this platform. A password reused from another site remains the most frequent cause of account compromise, and 2FA is the last line of defense, not a substitute for a good password.
I forgot my password
From the authentication page, the password recovery option sends a reset link to the account address, valid for 6 hours. After expiry, you request a new link.
The message displayed is identical whether or not the address is registered in the platform. The form only confirms that the request was submitted — this is an intentional data-protection measure. Consequently, if you don't receive the email, the on-screen message is not proof that the address is correct: first check whether you entered the address the account was created with, then check your spam folder. If the email still does not arrive, contact the support team.
Resetting your password does not disable 2FA
After you set a new password, the verification code will still be requested when you sign in. Password recovery and 2FA reset are entirely separate procedures.
I changed my email address
The new address must be confirmed through the link received by email. Until confirmation, the account remains associated with the previous address, which continues to work for authentication — so an unconfirmed change cannot leave you without access.
When the account is created, the address must also be confirmed before the first sign-in. The confirmation link does not expire.
I lost access to my email address
Without access to the account address you can no longer recover your password, receive 2FA codes by email, or receive the unlock link. Contact your organization's representative: the organization can disconnect the account and send you a new invitation, to your current address, from the staff administration area.
Your data is not lost. Only the link between the person and the authentication account is broken: your record and your history in the organization remain untouched. Once you accept the invitation, you sign in with the new address.
Exception: the Super User cannot be disconnected in this way; for them, access recovery is resolved together with the support team.
How long the session lasts
| Situation | Behavior |
|---|---|
| Ordinary session | expires after 30 minutes of inactivity; you are asked to sign in again |
| With “remember me” checked | the session does not expire through inactivity, for 2 weeks |
| Manual sign-out | ends the session and cancels “remember me” on all devices |
Don't check “remember me” on shared computers
On a shared or public device, this option retains access to your account for two weeks, without asking for either your password or your 2FA code.
My account is locked
The account is locked automatically after 10 failed sign-in attempts. The counter is shared across both factors: it counts wrong passwords and wrong 2FA codes alike. Ten wrong passwords lock the account even if you never reached the 2FA verification step.
On the 9th failed attempt you receive the warning „Mai ai o singură încercare până se blochează contul.” (“You have one attempt left before your account is locked.”) After locking, the message displayed is „Contul tău este blocat. Verifică contul de email pentru instrucțiuni deblocare.” (“Your account is locked. Check your email for unlock instructions.”)
Unlocking is self-service, by email:
- At the moment of locking, you automatically receive an email with an unlock link at the account address.
- If the email did not arrive or you no longer have the link at hand, you request another one from the authentication page (Didn't receive the unlock instructions?).
- Following the link unlocks the account and resets the failed-attempt counter.
The lock is not lifted by the passage of time — an action on your part is required. There is no point in waiting.
A second path: if you go through the password recovery procedure anyway and set a new password, the account unlocks automatically at that moment, without needing the unlock link. This is useful when the lock was caused by wrong passwords, so you no longer remember the correct one.
As with the password recovery form, the unlock form does not confirm whether the account exists: the message displayed is identical whether or not the address is registered in the platform.
Unlocking does not replace a 2FA reset. Unlocking only returns the counter to zero; 2FA remains active. If you entered the codes incorrectly but still have access to your 2FA method, unlocking is sufficient. If you have lost access to your 2FA method, unlocking solves nothing: the code will be requested again, and after 10 failed attempts the account will lock once more — see I lost access to my 2FA method.
See also
- Settings — how to enforce 2FA for all users of the organization (Super User only)
- Local Authentication and 2FA — the complete rules and normative values (the TOTP standard, thresholds, durations)
Settings
Advanced platform settings for ssm.ro — workplace supervisor, local accounts, language, employee import, email and STS signature.
Contact synchronization between organizations
How synchronization of contacts, positions, and departments works between two organizations, and how to activate the rule from your account.