Feesable takes security seriously. We have therefore implemented Multi-Factor-Authentication (MFA) which helps keep your information secure. MFA can be enabled optionally for any organisation (school). If MFA is enabled for your account, then this is setup in order to align with your school IT policy.
MFA might feel like unwanted extra steps, but those steps are what keep your digital world safe and sound. So, we encourage you to embrace MFA, and rest easy knowing you’re taking a big step towards keeping the data of your school and your families secure.
Here are a few common questions to help you learn more about MFA:
What is MFA?
Multi-factor authentication (MFA) is an important security measure used by Feesable to protect sensitive information and prevent unauthorised access to our systems and data.
MFA works by requiring users to provide two or more pieces of evidence to verify their identity when logging into our systems.
- The first piece of evidence is your username and password, like you’ve always done.
- The second, new, piece of evidence is a number that’s displayed on a device you own
Why are we implementing MFA?
By requiring multiple forms of authentication, MFA significantly reduces the risk of a security breach caused by stolen or weak passwords. Even if an attacker manages to obtain a user’s password, they would still need access to the second factor of authentication in order to gain access to our systems.
At Feesable, we take security very seriously, and we recognise that passwords alone are not enough to protect against today’s sophisticated cyber threats. That’s why we have implemented MFA as a standard security measure across all of our systems and applications.
We also require that our employees use MFA whenever accessing systems containing company or client data, as it can help protect against identity theft and other forms of cybercrime.
Install an Authenticator App on your device
If you already have an Authenticator app setup on your portable device or computer, read our Setting up MFA guide. If not, here are some of our favourites:
- Authy is free and known for its user-friendly interface and the ability to back up your authentication codes. This is helpful in case you change or lose your device.
- Lastpass – If you use the LastPass password manager, their free authenticator app is a good choice. It offers seamless integration with the LastPass manager and secure backup for your configuration.
- 1Password – If you use 1Password as your password manager, their authenticator feature can be handy. It keeps your passwords and MFA codes in one secure place.
- Google Authenticator is free and one of the most popular and widely used authenticator apps. It’s easy to set up and can be used for various online accounts.
- Microsoft Authenticator – If you’re in the Microsoft ecosystem, this app works well. It not only generates TOTPs but also supports push notifications for quick and easy authentication.
Remember, the effectiveness of an authenticator app isn’t just about the app itself; it’s also about how securely you use it. Make sure your device is protected with a strong PIN, password, or biometric lock. Also, consider enabling any available security features for the authenticator app itself, such as biometric access.
Do I need to enter an MFA code every single time I log in?
When you log in on a device, you can choose to “Remember this device”. This will allow you to login using just your username and password for the next 15 days. If you log in using a different device (or even a different browser on the same device) you will need to enter the MFA code again. Ensure you never use this option when you’re using a shared device
What if I lose my MFA device or can't use it?
If for some reason you cannot access your MFA device so can no longer authenticate, please contact [email protected] and we will reset your MFA so you can set it up again on the next login.
How often do I need to authenticate my browser?
Once you have logged in, your session will be logged out after 30 minutes of inactivity. If you checked ‘Remember this device” when logging in, you won’t need to re-do MFA until after 15 days.
Can I use MFA on multiple devices?
Yes, many MFA authenticator apps allow you to set up multiple devices for authentication, like your smartphone and a backup device, to ensure you’re not locked out if one device is unavailable. Check out the documentation for your chosen Authenticator app.
Can I turn off MFA if I don't like it?
Due to the sensitivity of data, and the implications of an account being hacked, we recommend you enable MFA, as it significantly boosts security.
If your school requires MFA, then all users associated with that school will also require MFA. This is a choice set by the school IT department.
MFA can however be disabled for a school, and hence all associated users, if desired.
Are there any additional costs to having MFA on my account?
No. We’re committed to protecting your account with the best security available. However, you may choose to use a paid Authenticator app on your phone or computer, instead of a freely available one such as Authy. This is entirely your choice.
For further questions or support get in touch at [email protected].