FriendHRM User Manual
Set up MFA and recover account access
Use an authenticator app when your tenant or platform policy asks for MFA, and use approved recovery paths when a device is unavailable.
Intended audience
- Admin
- HR
- Manager
- Employee
- SuperAdmin
Where to find it
Tenant access: Dashboard → Security → MFA. Platform access: SuperAdmin → MFA setup.
Before you start
- MFA is tenant-configured for tenant users and is not described here as universally mandatory.
- SuperAdmin MFA and recovery actions remain protected by platform policy.
Steps
- 1
Follow the enrollment prompt
When MFA enrollment is required, open the prompt or approved security page and scan the QR code with an authenticator app instead of manually retyping a secret unless the flow explicitly requires it.
- 2
Verify the current code
Enter a current one-time code from the authenticator app and wait for the product to confirm enrollment before leaving the setup flow.
- 3
Use the approved recovery route
If you lose the device, use an approved recovery code or contact the assigned security or platform owner; do not create a second identity to bypass MFA.
Expected result
The account remains protected according to the applicable tenant or platform MFA policy, with a documented recovery path if access is lost.
Open the relevant FriendHRM workspace
These destinations are verified against the current product navigation or route record. They remain subject to sign-in, feature, tenant, role, and data-scope checks.
Common problems
The authenticator code is rejected.
Check the device time, enter a newly generated code, and restart the approved enrollment or recovery process if the problem continues.