Two-Factor Authentication (2FA) adds a one-time, 6-digit code from an authenticator app to your normal username + password, significantly reducing the risk of account compromise.
In this guide
Turn on 2FA for your account
Log in with 2FA (and how password resets work with 2FA)
Manage or remove 2FA, and how admins can see who has it enabled
Username visibility & best-practice note
Below is a full list of supported mobile authenticator apps to use for your Two-Factor Authentication. We recommend Google Authenticator.
Android | |
iPhone |
Turn on Two-Factor Authentication
In BrightMove, click your profile picture (top-right) → My Profile → More → Enable Two-Factor Authentication.
When the QR code appears, open your authenticator app and add a new account by scanning the QR. If you can’t scan, choose Show Secret Key and add it manually in your app.
In BrightMove, click Next Step, enter the 6-digit code from the app, then Validate → Save. BrightMove Support
Log in with Two-Factor Authentication
Enter your username and password, then click Sign In.
When prompted, open your authenticator app and enter the current 6-digit Auth Code, then Sign In again.
Password resets when 2FA is on
If you choose Forgot Password:
Check your email and follow the link (or answer your Security Questions).
Enter the emailed code in BrightMove.
Set your new password and Save.
You’ll then be prompted for your 6-digit Auth Code from the authenticator app to finish signing in.
Manage Two-Factor Authentication
Turn off 2FA (your own account)
Profile picture → My Profile → More → Disable Two-Factor Authentication.
See who has 2FA enabled (admins)
Profile picture → Settings → Employees.
You’ll see a Two-Factor Enabled column indicating which users have set up 2FA.
Username visibility & best-practice note
Who can view a Username? Anyone who can view a user’s Employee or Hiring Manager profile can see that user’s Username. In most companies, this includes users with a Full user license (Recruiter and above), such as the Super User/Company Configurator and Admins.
Best practice: Avoid using a full email address as your Username. Email-style usernames can sometimes cause issues and may be flagged by the system, which can trigger a password-reset prompt.
Quick FAQ
Which authenticator app should I use? Any standard TOTP authenticator works; Google Authenticator is a common choice.
Do I need to re-enter the code if it expires mid-login? Yes—codes rotate every ~30 seconds. Open your authenticator and enter the current code.