Setup guide

Turn on two-step sign-in

Make everyone confirm their sign-in with a code from an app on their phone. Set up your own first, then your team is walked through it the next time they sign in.

For Owners, Managers, Everyone on the team 6 min read

1What two-step sign-in is

Two-step sign-in means a password alone can’t open your clinic’s Aminova. After the password, each person types a 6-digit code from an authenticator app on their phone. The code keeps changing, so a stolen password isn’t enough.

It is on for every clinic from the start. Nobody gets locked out by it: anyone who hasn’t set it up is walked through it the next time they sign in.

2Get an authenticator app

Each person needs a free authenticator app on their phone. Any of the common ones works. Install it from your phone’s app store before you start.

3Check it’s required

  1. 1Go to Settings, then Security.
  2. 2Under Two-Factor Authentication, make sure Require 2FA for all staff is switched on.
  3. 3It saves on its own.
Require 2FA for all staff, with your own authenticator just below it.
Require 2FA for all staff, with your own authenticator just below it.

4Set up your own

  1. 1Just below, find Your authenticator and press Set up.
  2. 2Open the authenticator app on your phone, add an account, and scan the square code on screen.
  3. 3Can’t scan it? Click Can’t scan? Enter the key manually and type the key into the app instead.
  4. 4Type the 6-digit code the app shows, then press Verify & enable.

5Save your backup codes

  1. 1Next you see a list of backup codes. They are shown only this once.
  2. 2Press Copy all and keep them somewhere safe, away from your phone, like a password manager or a locked drawer.
  3. 3Each code works one time, if you ever lose your phone.
  4. 4Press Done. Your authenticator now says Enabled, with how many backup codes you have left.

6What your team sees

  1. 1The next time each person signs in, after their password, they see a square code to scan.
  2. 2They scan it with their authenticator app, type the code under Verification Code, and press Verify & enable.
  3. 3They save their backup codes, tick I’ve saved my backup codes, and press Continue to workspace.

Tell your team before their next sign-in, so they have the app ready.

7Signing in each day

  1. 1After the password, open the app and type the code under Authenticator Code. Press Verify.
  2. 2On your own work computer, leave Remember this computer ticked. You won’t be asked for a code on it again for 30 days.
  3. 3Untick it on a shared or public computer.

Some important actions, like sending a prescription, ask for a fresh code even on a remembered computer.

8If you lose your phone

  1. 1On the code screen, press Lost your device? Use a backup code.
  2. 2Type one of your backup codes and press Verify.
  3. 3Once you’re in, set up your authenticator on your new phone.
  4. 4Running low on codes? Press Regenerate codes under Your authenticator for a fresh set, and save them again.

9Reset it for someone on your team

  1. 1If someone has lost both their phone and their backup codes, go to Team.
  2. 2Press Manage on their row, then Reset 2FA. You may be asked for your own code first.
  3. 3They set it up again the next time they sign in.
Team → Manage: Reset 2FA is in this menu.
Team → Manage: Reset 2FA is in this menu.

10More sign-in protection (optional)

  1. 1On the same Security page, set the Session Timeout: how long an idle computer stays signed in.
  2. 2Set Lock After N Failures and the Lockout Duration. Wrong codes count the same as wrong passwords.
  3. 3Add your office’s Trusted IP Ranges to flag sign-ins from anywhere else.
Session timeout, lockout, and your office’s trusted network addresses.
Session timeout, lockout, and your office’s trusted network addresses.

Rather be shown?

Inside Aminova, the tutorial walks you through every page, and the Getting started checklist shows you each task click by click. Or book a live training session with our team.