Qevlar supports multi-factor authentication (MFA) and configurable session timeouts to keep your account secure. MFA adds a second step at login - a short code from an authenticator app - so a password alone isn't enough to sign in. Session timeouts control how long you stay signed in before re-authenticating.
Setting up MFA (first-time enrollment)
When MFA is enabled for your account, you'll be guided through setup at your next login:
- Open any authenticator app (ex. Google Authenticator, Microsoft Authenticator).
- Scan the QR code on screen, or paste the setup key manually.
- Enter the 6-digit code from your app to confirm.
- Save your 10 backup codes somewhere safe. Each works once and lets you sign in if you lose your phone.
Logging in after enrollment
Enter your password as usual, then the current 6-digit code from your authenticator app. The code refreshes every 30 seconds.
Lost or replaced your phone?
- Use one of your backup codes in place of the app code.
- Out of backup codes? Ask your admin to reset your MFA, then re-enroll on your new device.
Managing your MFA (Security settings)
Go to Settings → Security to:
- Regenerate your backup codes (this replaces any old ones).
- Disable MFA (only available if MFA isn't required for your account).
For admins: enforcing MFA
- Per user: in User Management, set a user to Required (always use MFA) or Exempt (waive it, e.g. a service account).
Users set to Required stay enrolled even if enforcement is later turned off for the client.