Skip to main content

Two-Factor Authentication (2FA)

Add an extra layer of security with Two-Factor Authentication! Users must enter a 6-digit OTP for a safer login experience.

Written by Darrel

Two-Factor Authentication (2FA) adds an extra layer of security to your account login. When enabled, users must enter a 6-digit one-time passcode (OTP) in addition to their standard username and password when logging in. This passcode is sent to the user’s email address at the time of login.

When logging in from a trusted device, you can also choose to remember the device for 24 hours. This allows you to log in again during this period without entering another 2FA verification code.

1. 6-Digit One-Time Passcode (OTP)

A unique 6-digit OTP is sent to the user’s email address at every login. This adds a second layer of protection, ensuring that anyone attempting to log in must also have access to the recipient’s email account. Significantly reduces the risk of unauthorised access, giving users and admins alike peace of mind.

2. Invalid Attempts Lockout

Users who enter an incorrect OTP more than four times are blocked from logging in for 10 minutes. This security measure prevents repeated unauthorised attempts or brute-force attacks. Protects user accounts from persistent hacking efforts, further strengthening overall security.

3. Customisable 2FA Setting

Administrators can enable or disable 2FA for specific users within the Hotel or Chain Dashboard. Offers flexibility: security can be tailored to the needs of each user or department. Ensures that high-risk user accounts receive extra protection while others can maintain simpler login flows if necessary.

4. Session Duration and Re-Authentication

A user's session remains valid for 30 minutes, refreshing with continued activity. If the user becomes inactive, the session will automatically time out and they will need to log in again.

If Remember me was selected during the last successful 2FA verification, the device remains trusted for 24 hours. This means that if the session expires and the user logs in again from the same device within this period, they won't need to enter another 2FA verification code.

After the 24-hour period expires, or when logging in from a different device, 2FA verification will be required again.

5. Gradual Rollout and Default Settings

2FA is turned off by default for existing and new users. Allows your team to slowly introduce 2FA to the organisation, gather feedback, and make necessary adjustments.

Admins can enable it at their own pace, either for individuals or in bulk, allowing for a smooth, disruption-free rollout across the organisation.

How to Enable or Disable 2FA

  1. Open User Management [Only accessible for Hotel Manager Role in the Oaky dashboard]

    • Hotel Dashboard: Go to User Management and select the user you wish to edit.


  2. Toggle 2FA On/Off

    • Locate the 2FA setting (default is Off).

    • Switch to On to require an OTP at next login or leave it Off if not desired.


  3. Save and Confirm

    • Click Save to apply changes.

    • Once enabled, the user will be prompted for the 6-digit OTP during their next login.

Bulk Enable/Disable 2FA

For Hotel Dashboards

Hotels now have the option to enable or disable 2FA for all users at once with a single toggle.

  1. Navigate to User Management.

  2. At the top of the user list, use the 2FA toggle to apply the change for all users.

  3. A confirmation prompt will appear before the change is made.

This feature works both ways: quickly enabling or disabling 2FA for every user in the hotel with minimal effort.

For Chain Dashboards

The same bulk control is available for Chain Managers managing multiple hotels:

  1. Open the Chain Dashboard.

  2. Navigate to the list of users across the chain.

  3. Select specific users, or choose all users.

  4. Click the Enable/Disable 2FA option from the top.

  5. Confirm your action in the popup.

Once confirmed, the 2FA status will be updated across the hotels and reflected in each respective hotel dashboard.

Login Flow with 2FA Enabled

  1. Credentials: User enters their usual username and password.

  2. OTP Delivery: The system sends a 6-digit code to the user’s registered email.

  3. Code Entry: User enters the OTP on the login screen.

    • Incorrect code → “Invalid code” message.

    • Four invalid attempts → Blocked for 10 minutes.

  4. Access: Correct OTP → User is redirected to the dashboard as normal.

Remember Me on trusted devices

If you're logging in from a device you trust, you can select Remember me on the 2FA verification screen.

When Remember me is selected and your 6-digit verification code is successfully confirmed:

  • Your device will be remembered for 24 hours.

  • You won't be prompted to enter another 2FA code when logging in again from the same device during this period.

  • After 24 hours, you'll be asked to complete 2FA again as usual.

  • If you log in from a different device, you'll still be asked to enter a 2FA verification code.

The Remember me option is turned off by default, so you'll need to select it whenever you want Oaky to remember a trusted device.

Security tip: Only select Remember me on a device you trust and control. Avoid using this option on shared or public devices.

FAQ

  1. Do I need to enter a code every single time I log in?
    Not necessarily. If you select Remember me when completing 2FA, your device will be remembered for 24 hours. During this period, you won't need to enter another 2FA code when logging in again from the same device.

    After 24 hours, or when logging in from a different device, you'll be asked to enter a new 6-digit verification code.

  2. What if I lose access to my email?
    You won’t be able to retrieve the OTP. Contact your hotel’s administrator or support team for assistance in getting access to your hotel’s email account.

  3. Will I get logged out if I close my browser tab?
    Not immediately. If you reopen the browser within the active session period, you can remain logged in. Inactivity beyond 30 minutes will cause your session to time out.

    If your session has timed out but your device is still within the 24-hour Remember me period, you can log in again without completing 2FA.

  4. How long does Oaky remember my trusted device?

    When you select Remember me and successfully complete 2FA, Oaky remembers that device for 24 hours.


    During this period, you won't be asked for another 2FA verification code when logging in from the same device. After 24 hours, 2FA verification will be required again.

  5. Is 2FA mandatory for all users?
    Not by default. It’s disabled unless a hotel or chain manager enables it for specific user accounts.

Did this answer your question?