Skip to main content
Team & security

Two-factor authentication and account recovery

Use passkeys or authenticator-based two-factor sign-in, store one-time backup codes safely, review active sessions, and understand controlled recovery.

ReviewedAugust 21, 2026

Passkeys and authenticator-based two-factor authentication protect account access and sensitive actions. Your firm may require every member to enrol an authenticator.

Add a passkey or authenticator

  1. Open Settings → Security.
  2. Add a passkey on a trusted device, or scan the QR code with your authenticator app and enter the current code.
  3. Store the one-time backup codes somewhere separate from your password and device.

Review active sessions

Use the active-session list to sign out devices you no longer recognize or use. Password and two-factor changes revoke older sessions.

If you lose access

Use an unused backup code or the verified-email recovery path available to eligible accounts. Privileged accounts keep stricter recovery requirements, and another authorized firm administrator can reset a locked-out member's second factor. New security-question recovery is not offered.

Was this helpful?

Tell us what was missing and we’ll improve this guide.

Send feedback