Troubleshooting Two-Factor Authentication (2FA) in SIX ERP

Two-Factor Authentication (2FA) greatly improves security, but it also means that if the second step fails, you can’t log in—even if your username and password are correct.

This article explains the most common causes of 2FA problems, what you can try yourself, and when you must contact a system administrator to recover your account.

⚠️ Important:
In most cases of 2FA failure or lockout, you will need to contact your system administrator. Users cannot bypass or disable 2FA on their own once they’re locked out.

1. Typical symptoms of 2FA problems

You may encounter one or more of these issues:

These are usually caused by a few recurring issues.

2. Main reasons for 2FA issues

2.1 Code not received (Email, WhatsApp, Viber)

Typical reasons:

What you can try:

If nothing arrives after multiple attempts, contact your administrator.
They may need to correct your email/phone number or temporarily change your 2FA method.

2.2 Code entered but “invalid”

This can happen with Email, WhatsApp/Viber, or Authenticator App codes.

Typical reasons:

What you can try:

If codes are still “invalid” every time, you may need your 2FA setup reset by an administrator.

2.3 Code expired / session timeout

With 2FA in SIX ERP there are two time limits:

  1. The code’s lifetime (usually 60 seconds for authenticator apps).

  2. The SIX ERP session timer on the 2FA screen (how long the system waits for a code).

Problems occur when:

Typical scenario with authenticator apps:

What you can do:

2.4 No access to email / phone / authenticator device

This is the most serious and common cause of hard lockouts:

In all these cases you cannot receive or generate codes at all.

In these situations, you cannot recover access by yourself.
You will need help from a system administrator.

An administrator can:

2.5 Wrong or unexpected 2FA method active

Sometimes problems arise simply because the “wrong” method is enabled or expected:

What you can do:

The administrator can then adjust your method accordingly.

3. When you must contact a system administrator

You should stop retrying and contact an administrator when:

When contacting your administrator, it helps to provide:

Remember: Administrators are the only ones who can override, reset, or disable 2FA for security reasons.

4. Best practices to avoid future 2FA problems

To minimize 2FA issues:

Two-Factor Authentication in SIX ERP
Security in SIX ERP
Setting up email two-factor authentication
Setting up TOTP two-factor authentication with an Authenticator App
Setting up two-factor authentication with WhatsApp
Best Practices for maintaining secure connections to your ERP