sklera 4.0.1 introduces a long awaited and much requested feature: 2 Factor Authentication (2FA).

The activation of 2FA is optional, but recommended due to the added account security this feature offers.


Prerequisite for using the 2FA is a E-Mail address associated with your sklera user or the usage of a mobile authenticator (like Google Authenticator, Microsoft Authenticator, Authy or Duo Mobil).


Setting Up 2FA

To activate 2FA for your user go to the user menu in the top right of the sklera CMS and enter the user settings. You'll find a green button labeled 'Activate' under 2FA.


Once you click the 'Activate' button you'll have the choice of either using your E-Mail address or a mobile authenticator app as second factor.


Using your E-Mail

Enter the E-Mail address you'll be using as a second factor. By default this is the E-Mail address associated with your user account. We'll e-mail you a one time code. Enter it to activate the factor.


Note: if the E-Mail does not arrive in a timely manner (within 1-2 minutes, usually), please check your spam folder and/or resend the verification e-mail.


Using an App

Open the authenticator app of your choice and proceed to scan the QR code displayed on your screen. This will add the sklera CMS, and continually generate new security codes. Enter the currently valid code in the input field below the QR code and confirm by pressing the button.


Removing 2FA from your Account

Once 2FA is active it can be removed by going to your user settings and pressing the corresponding button there. You'll need to verify the action by entering the second factor.


In case you have lost access to your second factor (e.g. lost your phone or new phone, or lost access to your E-mail) please contact the support address listed in your sklera CMS, or us directly so we can forward the request to the appropriate contact.


Protect Screens with 2FA

You can activate Screen protection under More -> Settings. If enabled, attempting to delete a screen will trigger a 2FA challenge and prompt you to enter a 2FA token (either via E-Mail or from your Authenticator App).


Channel Setting for Resellers: Force 2FA

Resellers now have the option to require 2FA for all users assigned to a certain channel. This setting can be toggled when editing a Channel's features.