Two-Factor Authentication (2FA) in SIX ERP adds an extra layer of protection to your account by requiring something you know (your password) and something you have (a one-time code) before granting access. In SIX ERP this helps protect user accounts, company data, and systems from unauthorized access—even if someone knows your password.
This article explains which 2FA methods are available and what users need to do when 2FA is enabled on their account.
SIX ERP currently supports these verification types:
Two-Factor Authentication (2FA) in SIX ERP adds an extra layer of protection to your account by requiring something you know (your password) and something you have (a one-time code) before granting access. In SIX ERP this helps protect user accounts, company data, and systems from unauthorized access—even if someone knows your password.
These are the standard options; which ones you see depends on how your instance is configured:
You receive a 6-digit passcode by email.
You enter this code on the 2FA screen shown right after your normal login.
You use Google Authenticator or Microsoft Authenticator (or any compatible TOTP app).
After login, you enter the time-based code shown in your authenticator app.
These two together are considered the default 2FA types in SIX ERP.
Depending on your contract and setup, a third channel can be enabled:
You receive a verification code via the configured messaging app and enter it on the 2FA screen.
Availability of WhatsApp/Viber is client-specific and may require activation by SIX support or your system administrator.
Once 2FA is enabled for your account or instance:
Enter your username and password as usual.
If credentials are correct and 2FA is required, SIX ERP shows a Two-Factor Authentication screen.
Depending on your configured 2FA method, you must:
Enter the 6-digit email code, or
Enter the code from your Authenticator App, or
Enter the code received via WhatsApp/Viber.
If the code is valid, you are fully logged in and can access SIX ERP.
If the code is invalid, expired, or missing, access is denied and you may need to retry or log in again.
When your 2FA method is Email authentication, this is what happens after you log in:
Login with username and password.
You are redirected to the Two-Factor Authentication screen asking for a 6-digit code.
SIX ERP sends an email to your registered email address containing this one-time code.
Open your email inbox and find the message (check Spam/Junk if you don’t see it).
Enter or copy the 6-digit passcode exactly as shown in the email (no spaces).
Confirm/submit the code in the interface.
If the code is valid, your login completes and you are taken into the system.
No email received?
Wait a few seconds and refresh your inbox.
Check Spam, Junk, or Promotions folders.
Make sure you’re checking the correct email account (the one linked to your SIX ERP user).
If you still don’t receive anything, contact your administrator or IT.
Code doesn’t work?
Make sure you copied all 6 digits correctly.
Avoid extra spaces before or after the code.
Request a new login and new code if needed.
Security note: Each code is intended for one login only and shouldn’t be reused or shared with anyone.
When you use Google Authenticator or Microsoft Authenticator, SIX ERP relies on time-based one-time passwords (TOTP). These codes:
Change automatically every 60 seconds.
Are generated on your mobile device.
Must be entered quickly before they expire.
This article focuses on using the authenticator once it’s set up. Initial setup & pairing will be covered separately in an admin/setup guide.
Login with username and password to SIX ERP.
After login, you see the Two-Factor Authentication screen asking for a code.
On your phone, open Google Authenticator or Microsoft Authenticator.
Find the entry for your SIX ERP account/tenant.
You’ll see:
A 6-digit (or similar) code, and
A countdown timer showing how long the code is valid (typically 60 seconds total).
Check that there is sufficient time left (ideally more than a few seconds).
Type the current code into the SIX ERP 2FA screen.
Confirm/submit the code.
If the code is correct and entered before the timer reaches 0, your login completes.
Codes rotate every 60 seconds.
When the countdown reaches 0, that code is no longer accepted.
If the timer runs out before you submit, or you submit after expiry: The verification will fail.
You will need to restart the login with your username and password and try again with a fresh code.
Be quick but accurate:
Avoid waiting until the last 2–3 seconds of a code’s life.
If the timer is nearly at 0, wait for the next code and then enter it.
Code always invalid:
Make sure you’re using the correct account in the app (some users have multiple accounts).
Ensure the time on your phone is set automatically (incorrect device time can break TOTP codes).
If the problem persists, contact your administrator to reset your 2FA setup.
Lost/broken phone: You will not be able to generate codes. Contact your administrator or SIX support to disable or reset 2FA and configure a new device or method.
For some clients, SIX ERP can be configured to send 2FA codes via WhatsApp or Viber instead of email or authenticator apps.
The flow is similar to email 2FA:
Login with username and password.
The Two-Factor Authentication screen appears.
SIX ERP sends a verification code to your configured WhatsApp or Viber number.
Open WhatsApp/Viber on your phone.
Find the message containing the verification code.
Enter the code into the 2FA screen in SIX ERP and submit.
If you don’t receive a message or the code doesn’t work, follow the same troubleshooting logic as with email (check connectivity, confirm number, retry login, or contact your administrator).
Note: The availability of WhatsApp/Viber authentication depends on your tenant configuration and contract. If you don’t see this option but need it, discuss it with your system owner or SIX support.
These are the standard options; which ones you see depends on how your instance is configured!
The availability of WhatsApp/Viber authentication depends on your tenant configuration and contract. If you don’t see this option but need it, discuss it with your system owner or SIX support.
See also:
Security in SIX ERP
Setting up email two-factor authentication
Setting up TOTP two-factor authentication with an Authenticator App
Setting up two-factor authentication with WhatsApp
Troubleshooting two-factor authentication
Best Practices for maintaining secure connections to your ERP