Overview
Provet offers two-factor authentication (2FA) features to increase the security of user accounts. When enabled, users must periodically verify their identity in two steps:
The user logs in with their password.
A 6-digit verification code is sent to the user and must be entered to complete login.
Once entered correctly, the user is logged in. Successful 2FA verification remains valid for 30 days, after which the user must re-authenticate.
Note
Note: If a custom authentication method such as SAML2 or LDAP is in use, 2FA is not available.
Delivery methods
2FA codes can be delivered by SMS or email. You can select the delivery method that is suitable for your clinic.
SMS: The code is sent to the phone number listed on the user's profile. If no phone number is saved, the user is prompted to enter one before receiving the code.
Email: The code is sent to the email address associated with the user's account. No additional apps or phone number are required.
Enabling 2FA
To enable two-factor authentication for your clinic:
Go to Settings > Users > Password settings.
Select the Enforce two-factor authentication for all users in this organization option.
Note
To disable 2FA, unselect Enforce two-factor authentication for all users in this organization. Disabling 2FA is not recommended, as it reduces account security.
Selecting the delivery method
Admins can configure which delivery method is used for 2FA codes. Email 2FA is available without any additional setup and does not require users to have a phone number on their profile. To select the delivery method, go to Settings > Users > Password settings and select the preferred option from the One-time passcode retrieval method dropdown list.
Skipping 2FA for specific IP addresses
You can exclude specific IP addresses from 2FA requirements. For example, you may want to allow users on the clinic network to skip 2FA while still requiring it for logins from other locations.
Go to Settings > Users > Password settings.
Find the Skip two-factor verification from specific IP addresses field and enter the relevant address.
Note
IP addresses must be entered in CIDR notation.
