What is MFA and Why is it Required?
Multi-Factor Authentication, or MFA, is a security protocol for verifying a person’s identity through the use of multiple credentials while logging in to Divvy.
For example, a person inputs their username and password to log in to Divvy on the web (first credential), then receives a text message on their phone to input a unique code in their browser (second credential).
Overall, MFA enhances security beyond just a username and password. Usernames and passwords can be stolen or compromised through a variety of methods (phishing, system breaches, insecure password practices, credential stuffing, etc). MFA safeguards your company's information and employees by adding an additional layer of protection so that even if credentials are compromised, a malicious actor still cannot log in and wreak havoc on your company in Divvy.
Currently, all Divvy users are required to set up MFA in order to access their account.
MFA Options Supported in Divvy
There are currently two options supported for multi-factor authentication in Divvy:
SMS/Text MFA — a one-time code is sent to your mobile device as a text message used to log in to Divvy.
Authenticator app — a separate mobile or web app is used to generate one-time codes used to log in to Divvy.
1. Do I have to complete MFA every time I log into Divvy?
A: No. If you set the “Remember this browser” setting when logging in, you will only have to MFA once every 60 days. If you are using incognito mode, new devices, or blocking cookies, you will be prompted to MFA more often.
2. Is there a cost for SMS/Text MFA that I should be aware of?
A: Normal text messaging rates apply when using SMS/Text as the MFA option on your account.
3. I don’t have a phone or the ability to receive SMS/Text messages for MFA. What can I do to continue logging into Divvy?
A: We recommend using a web-based authenticator app in these circumstances. One we recommend is 1Password. If this option does not meet your needs, please contact Divvy Support for assistance.
4. I lost my phone or got a new mobile device. How can I access my Divvy account?
A: Your company administrator can reset MFA for you or our Divvy Support team can also assist you. If you contact Divvy Support, please be prepared to answer some questions to confirm your identity.
5. I am getting an error message: “Invalid phone number - please try again” when registering with SMS/Text MFA. What does this mean?
A: Make sure you are inputting a 10-digit phone number (for US numbers) and not including a “1” in front of your phone number. Also, do not include any hyphens (“-”) or dashes (“/”) in your phone number.