# Two-factor authentication (2FA)

Get answers to all of your questions regarding Brex

**URL Source:** https://www.brex.com/support/two-factor-authentication

---

## Overview

Two-factor authentication (2FA) is an extra layer of security that prevents unauthorized access to your account. 2FA is achieved by either setting up SMS authentication or installing a general-purpose authenticator app on your mobile device. 2FA is required for all Brex users.  
  
**We recommend using an authenticator app (see examples below). Authenticator apps provide greater security than SMS, and can be used without a working cell network.   
  
**Brex doesn’t require installation or download of a browser extension to access your account. You should always exercise caution when installing browser extensions.



**Note:** Brex will never call you asking for your 2-Factor Authentication (2FA) code or any one-time passcode.

## How it works

When you sign in to Brex using 2FA, you’ll receive a prompt to provide a verification code in addition to your password. Brex offers two ways to receive a code:

- **[Recommended] **Authenticator app (e.g., Google Authenticator, Twilio Authy, Okta, Duo, 1Password)
- SMS text message

Please read the relevant section below to either set up 2FA for the first time or switch from one method to the other.  
  
**Note:** If you’re using SSO as your preferred sign-in option, you won’t need to complete 2FA during sign-in.

## Setup

### Authenticator app setup

**Step 1:** Download an authenticator app.

- Google Authenticator: [iPhone](https://itunes.apple.com/us/app/google-authenticator/id388497605?mt=8/), [Android](https://play.google.com/store/apps/details?id=com.google.android.apps.authenticator2&hl=en/)
- Twilio Authy: [iPhone](https://apps.apple.com/us/app/twilio-authy/id494168017/), [Android](https://play.google.com/store/apps/details?id=com.authy.authy&hl=en/)
- Okta: [iPhone](https://apps.apple.com/ca/app/okta-verify/id490179405),[ Android](https://play.google.com/store/apps/details?id=com.okta.android.auth&hl=en_US&gl=US)
- Duo Mobile: [iPhone](https://apps.apple.com/us/app/duo-mobile/id422663827https://apps.apple.com/us/app/duo-mobile/id422663827),[ Android](https://play.google.com/store/apps/details?id=com.duosecurity.duomobile&hl=en_US&gl=US&pli=1)

**Step 2:** After downloading your app of choice, ensure that your device's date and time settings are configured to _Automatic_ mode. Authenticator apps generate 2FA codes using the current time on your device, so if the time is set incorrectly, the wrong code will be generated.  
  
**Step 3: **Click your company name at the top left of your dashboard and go to _Personal settings > Security and privacy._  
  
**Step 4: **Under _Personal_, find _Two-factor authentication _and click _Change method_.  
  
**Step 5: **Choose _Authenticator app_ and click _Continue_.  
  
**Step 6: **Open your authenticator app and use it to scan the QR code, then click _Continue_.  
  
**Note: **If you can’t scan the QR code, choose manual entry on your app, and enter the code shown on the screen.  
  
**Step 7:** Enter the six-digit code from your authenticator app and click _Continue _(the code typically expires after 30 seconds).  
  
**Step 8: **Copy or download the recovery codes and save them in a secure place, then click _Continue_.  
  
Once 2FA is enabled, it cannot be disabled.** If you ever lose your phone, you can use your recovery codes to sign in to Brex. Each recovery code can be used once.  
  
**If you do not have access to your recovery codes, you can contact your admin to receive a one-time recovery code via email.

### SMS text message setup

**We strongly recommend using an authenticator app, as this provides greater security and does not require a working cell network to use. However, if you prefer to use SMS messaging, please follow these instructions.  
  
Step 1: **Click your _c_ompany name at the top left of your dashboard and go to _Settings_.  
  
**Step 2: **Under_ Security and privacy_, find _Two-factor authentication_ and click _Change method_.  
  
**Step 3: **Choose _Text Message _and click _Continue_.  
  
**Step 4: **Enter the phone number you want your code sent to and click _Continue_. This phone number will replace any existing phone number on your account and will be used for customer communications and fraud prevention moving forward.  
  
**Step 5: **Enter the six-digit code sent to your phone number and click _Continue_ (the SMS code will typically expire after three minutes).  
  
**Note: **Once 2FA is enabled, it cannot be disabled.  
  
**If you don’t receive your SMS code, your admin can generate a one-time recovery code via email.**

## Reset 2FA

If your 2FA code has stopped coming through, you or your admin can reset your 2FA method

### For users

Please contact your Brex admin to reset your 2FA.

### For admins

If a member of your team is unable to access their account as their phone number has changed, admins have the ability to send a 2FA recovery code by email. To do so, please follow the steps below:  
  
**Step 1:** In your Brex dashboard, go to _Teams.  
  
_**Step 2: **Click on the user who needs to have their 2FA reset.  
  
**Step 3: **Click _User actions _> _Send 2FA recovery code_ > _Send code_.  
  
This will send an email to the address your employee has on file that includes the recovery code and instructions to reset their 2FA settings. This code will only be valid for 2 hours. To complete the 2FA reset and to ensure that their 2FA is reset moving forward, the user will need to follow the setup steps listed above.