Skip to content
English - Australia
  • There are no suggestions because the search field is empty.

How to Set Up Multi-Factor Authentication (MFA)

Secure your Mastt workspace with multi-factor authentication for construction project teams

Multi-Factor Authentication (MFA) adds an extra layer of security to your Mastt workspace by requiring a verification code from an authenticator app each time users sign in. This guide covers how to enable MFA, complete the user setup process, and reset MFA if needed.

MFA applies to users who sign in with an email and password. If your workspace uses Microsoft or Okta SSO, those users are already authenticated through your identity provider and won't be prompted for MFA.

Before You Start

  • You need Workspace Admin access to enable MFA or reset it for other users
  • Each user needs an authenticator app installed on their mobile device (e.g. Google Authenticator, Microsoft Authenticator, or Authy)

Enabling MFA for Your Workspace

This is a one-time setup performed by a Workspace Admin. Once enabled, all users in the workspace will be required to set up MFA.

Navigate to Workspace Security Settings

  1. Click your profile icon in the top-right corner and select Admin.
  2. Click Workspace Details.
  3. Scroll to the Security section.

Turn On MFA

  1. Find the Require multi-factor authentication (MFA) toggle and turn it on.
  2. Choose when MFA takes effect:
    • Click Immediately — every user is prompted to complete MFA setup the next time they sign in, and must finish it to continue.
    • Click From a Date and choose a date in the Enforcement date field. Members will be prompted to set up MFA right away, but it won't be enforced until the selected date — until then, they can skip the prompt and keep working as normal.
  3. Set how often users need to re-verify:
    • Leave Require MFA on every sign-in off (the default) to apply a grace period — once a user signs in with MFA, they won't be asked again until the number of days set in Days before MFA is required again has passed. This defaults to 30 days, but you can manually enter a different number if you want a shorter or longer grace period.
    • Turn Require MFA on every sign-in on if you want users to enter a code every time they sign in, with no grace period.
  4. Click Save.

If you schedule a future enforcement date, let your team know ahead of time. They'll start seeing the setup reminder right away, but won't be locked out until the date you've chosen. 

Setting Up MFA as a User

This process happens automatically the first time you sign in after a Workspace Admin has enabled MFA.

Complete the MFA Setup

  1. Sign in to Mastt with your email and password.
  2. Open your authenticator app and scan the QR code.
  3. Click Continue. Your MFA setup is now complete.

If you can't scan the QR code, select the option to enter the setup key manually, then enter the 6-digit code from your authenticator app and click Verify & sign in.

Signing In with MFA

After your initial setup, you'll usually be asked for a verification code each time you sign in.

Mastt applies a grace period after a successful MFA sign-in — 30 days by default, though your Workspace Admin can change this in Days before MFA is required again (unless they've turned on Require MFA on every sign-in). You won't be asked for a code again until that period has passed.

Enter Your Verification Code

  1. Enter your email and password as usual.
  2. Enter the 6-digit code from your authenticator app.
  3. If the code is correct, you will be signed in automatically.

Resetting MFA for a User

If a user loses access to their authenticator app, a Workspace Admin can reset their MFA so they can set it up again.

Reset a User's MFA

  1. Click your profile icon in the top-right corner and select Admin.
  2. Click User Management.
  3. Select the user who needs their MFA reset.
  4. Click the Action button.
  5. Click Reset MFA. The user will be prompted to set up MFA again the next time they sign in.

Troubleshooting & FAQs

Q: What happens if I enter the wrong verification code?

If you enter an incorrect code five times, you'll see an error message asking you to wait. Wait five minutes, then try again using a fresh verification code from your authenticator app.

Q: Can I use any authenticator app?

Yes. Any TOTP-compatible authenticator app will work, including Google Authenticator, Microsoft Authenticator, and Authy.

Need Help?

Contact Mastt Support for additional assistance with Multi-Factor Authentication.