Enable and manage MFA on the candidate portal

Enable and manage MFA on the candidate portal

How do I enable and manage MFA on the candidate portal ?

Multi-factor authentication (MFA) adds an extra layer of security to your candidate account. It verifies your identity using a second method (mobile authentication app or code sent by email) in addition to your password. This protects your account even if your password is compromised. If the administrators of the program platform you are participating in have made MFA mandatory, you will be prompted to set it up the next time you log in, depending on the activation deadline predetermined by the administrators.

Enabling MFA on the candidate portal

To enable MFA on your portal, please follow these steps :

  1. Enter your login credentials, then click “Continue.”


  1. You will be redirected to this interface, where you will need to activate your MFA (multi-factor authentication) by choosing one of the two methods offered: use an authentication app (highly recommended) or receive a code by email.
Notes
It is possible to activate and use both MFA methods in parallel.


  1. If you are using an authentication application, click the “Configure” button located just in front of this method.



  1. Next, you will need to use a dedicated authentication app, such as Google Authenticator, installed on your phone. When activating MFA (multi-factor authentication), you will be provided with a QR code on the platform. Simply scan it with the app and it will start generating temporary one-time codes. If you are unable to scan the QR code, you will also be given a secret key consisting of 16 alphanumeric characters, which you can enter manually into the authentication app. Once the app is configured, enter the validation code generated and click on the “Validate” button to confirm the activation of MFA.




  1. You will then be taken to an interface containing recovery codes, accompanied by the following message: “These codes are only visible once. Save them in a safe place. You can regenerate them later as long as you are logged in.” You will need to click on the “Download as .txt” button to save these codes to your device.



  1. Once MFA (multi-factor authentication) activation has been validated using the authentication application method, the interface will display a blue check mark next to the name of the selected method. This confirms that the activation has been successfully completed.


  1. If you are using email authentication, click the “Configure” button located just in front of this method.


  1. Click on the “Send code” button.


  1. Next, copy the code you received in your inbox,



  1. Paste it into the field provided, then click on the “Validate” button.


  1. Once MFA (multi-factor authentication) activation has been validated using the email authentication method, the interface will display a blue check mark next to the name of the selected method. This confirms that the activation has been successfully completed.



Alert
The “Skip” button is displayed until the activation deadline set by the administrator has passed. You can use it to temporarily skip MFA activation until that date. Once the deadline has passed, MFA activation becomes mandatory.


Manage MFA in the candidate area

After activating your multi-factor authentication (MFA), you can deactivate it, delete a method, or add a new one. To do so, follow these steps:
  1. Click on your profile icon, then “Security.”


  1. From your personal space, you can manage your MFA methods: delete those that are already activated or add new ones.
Notes
If you add a new method, you will need to repeat the process as explained earlier in this article, depending on the method.


  1. To delete the authentication application method, click on the delete icon (usually represented by a trash can) located directly opposite the method in your personal space.


  1. Enter the one-time authentication code generated by your authentication app, then click the “Validate” button to disable this method.



  1. Your app-based authentication method has been successfully deleted. You can add a new one at any time from your personal account.



  1. To delete the email authentication method, click on the delete icon (usually represented by a trash can) located directly opposite the method in your personal space.



  1. Next, copy the code you received in your inbox,


  1. Paste it into the field provided, then click on the “Validate” button.



  1. Your email authentication method has been successfully deleted. You can add a new one at any time from your personal account.



Alert
If you lose access to your multi-factor authentication method (for example, if you lose or change your phone), you can use your recovery code as a backup solution to access your account.

  1. Recovery codes are generated when you activate MFA. If you have lost them, you can generate new ones by clicking on the “Generate” button in your personal space.



  1. Then click on “Generate.” 


  1. New recovery codes have been successfully generated. The old codes are automatically deactivated.