Skip to main content

Two-step login

Two-step login (also known as two-factor authentication or 2FA) prevents anyone from maliciously accessing your Bravura Safe data (even if they somehow get your master password) by requiring authentication from a secondary device when you log in.

Many different methods are used for two-step login, including: authenticator apps, email and hardware security keys.

Two-step login is used at two levels for Bravura Safe:

  • Enterprise Team two-step login (for everyone)

  • Individual safe two-step login (for you only)

The following topics show you how to modify two-step login for yourself. For details on enforcing Enterprise two-step login, see Enforce Enterprise two-step login .

Note

Individual two-step login can be enforced by the Enterprise Team administrator via Teams > [Enterprise Team] > Settings > Policies > Require two-step login.

New users are automatically set up with Bravura OneAuth and/or two-step login via email. This can be changed as desired.

To configure two-step login for your individual safe:

  1. Open and log in to the Bravura Safe web interface.

  2. Click on the profile menu at top right (your initials/avatar).

  3. Select Account settings.

  4. Select Security from the ACCOUNT SETTINGS menu.

  5. Click on the Two-step login tab.

  6. Locate the desired Provider and click Manage.

  7. Follow the displayed instructions (see examples below) and click Turn on.

See examples below:

Authenticator app

safe_web_ind_twostep_authapp

Email

safe_web_ind_twostep_email

Bravura OneAuth

The following topics show you how to install the HYPR app that powers Bravura OneAuth, pair your phone to Bravura OneAuth during login, and manage paired devices.

The HYPR oneauth_hypr_app_icon mobile app allows you to securely authenticate to Bravura Security Fabric from anywhere.

  1. Download and install the HYPR mobile app by using one of the following links:

    • The HYPR app for Android is available for download from Google Play.

    • The HYPR app for Apple iOS is available for download from the App Store.

  2. Follow the instructions on your mobile device to set up biometric authentication (Touch ID or Face ID).

After you have installed the HYPR app on your device and set up biometric authentication (Touch ID or Face ID) you can pair your phone to Bravura OneAuth during Bravura Security Fabric login.

  1. Open the Bravura Safe application on your computer or mobile device. See First steps.

  2. Log in.

    Bravura OneAuth automatically detects if you do not yet have a mobile device registered for authentication.

    safe_login_oneauth3_no_device_found
    1. Click or tap Send registration email.

  3. On your mobile device:

    1. Open the Bravura Security Fabric " Bravura OneAuth device registration" email.

    2. Tap Register Device.

      safe_login_oneauth_mobile3_get_started
    3. Tap Get Started.

      A Bravura OneAuth web account is created using your email address, and your mobile device begins pairing:

      safe_login_oneauth_mobile4_pairing

      A prompt appears for biometric authentication:

      safe_login_oneauth_mobile5_touch_id

      Note

      In this example, the user has configured Touch ID. You may also use Face ID.

    4. Authenticate to Bravura OneAuth using your mobile device's configured biometric method.

      You may be prompted with PIN enrollment.

      hypr_app_pin H 800
    5. Enter and confirm a 6-digit PIN.

      Pairing continues.

      safe_login_oneauth_mobile4_pairing
      safe_login_oneauth_mobile6_successfully_paired

      After successful biometric authentication, your device is successfully paired to your Bravura OneAuth web account.

    6. Tap OK.

      Bravura OneAuth displays your application web account.

      safe_login_oneauth_mobile7_account
    7. Tap the account row to view details; for example, the associated email address.

      Note

      You may register/pair multiple devices to your Bravura OneAuth web account via Bravura Safe and the Bravura OneAuth Device Manager.

      See Manage registered (paired) Bravura OneAuth devices.

You may now log in to Bravura Safe using your master password and Bravura OneAuth.

After you have installed the HYPR app on your device and set up biometric authentication (Touch ID or Face ID) you can pair your phone to Bravura OneAuth via a magic link on your web browser. A magic link is usually sent in your invitation email.

  1. On your computer:

    1. Open your email to locate the message containing the magic link (URL) that was sent to you by your Bravura OneAuth administrator.

    2. Click the link.

    3. Bravura OneAuth Device Manager opens.

      oneauth_pair_what_device H 500
    4. Under "What device would you like to pair?" click Smartphone.

      A QR code and instructions are displayed.

      oneauth_pair_scan_qr H 500
  2. On your phone:

    1. Open the HYPR oneauth_hypr_app_icon app.

      hypr_app_taptoscan H 500
    2. Tap the scan icon located at the top right.

    3. Aim your phone's camera at the QR code on the computer screen.

      Your phone will begin pairing to Bravura OneAuth and then prompt for biometric authentication.

      Note

      In this example, the user has configured Touch ID. You may also use Face ID.

      hypr_app_touchid H 500
    4. Authenticate to the HYPR app using a biometric authentication method configured for your device (Touch ID, Face ID).

      You may be prompted with PIN enrollment.

      hypr_app_pin H 800
    5. The HYPR app will indicate that your phone has been successfully paired to your Bravura OneAuth account.

    6. Tap OK.

      The HYPR app shows the paired application account. If your phone is paired to more than one Bravura OneAuth account, they will all be listed here.

      hypr_app_account H 500
    7. Click on an account to view details (such as your Username/email address).

      Tip

      You can delete an account from this screen.

      hypr_app_account_open H 500
  3. On your computer:

    1. The Bravura OneAuth Device Manager will display your paired device.

      oneauth_pair_my_devices H 500

      Tip

      From this page, you can Add Another Device to your Bravura OneAuth account, or Unpair an existing device.

    2. Click Logout to log out from Bravura OneAuth Device Manager and then close the browser tab.

      oneauth_pair_logged_out H 500

Once you have successfully paired your phone to your Bravura OneAuth account using the magic link, you will be able to use Bravura OneAuth as a second factor to authenticate to Bravura Safe.

These instructions assume that Bravura OneAuth has been enabled for your enterprise and the following steps have been completed:

  • Set up biometric authentication (Touch ID or Face ID) on your mobile device

  • Install the HYPR app on your phone

  • Invited/accepted/confirmed to a Bravura Safe Team

  • Created a Bravura Safe account with a master password

On your computer or mobile device

  1. Open the Bravura Safe application:

    Web interface (shown below): Navigate to your company's Bravura Safe instance URL.

    Desktop or Mobile: Open the Bravura Safe application.

    safe_web_login_email
  2. Enter your Bravura Safe account Email address.

  3. Optionally, select or toggle on Remember email so you do not have to enter it next time.

  4. Click or tap Continue.

    safe_web_login2_w3buttons
  5. Enter your Bravura Safe account Master password.

  6. Click Log in with master password (tap Log in for mobile).

    Note

    When Bravura OneAuth is configured/enabled for the enterprise (global) Team, it will be used as the default second factor of authentication for all users accessing Bravura Safe.

    A "Check device for notification" prompt appears.

    oneauth_check_device
  7. If you have not yet paired your mobile device, see Pair your phone to Bravura OneAuth during Bravura Safe login.

Note

If you've forgotten or lost your phone, see Replace a paired mobile device.

A lost phone should be reported immediately to your IT department so it can be de-authorized.

On your phone

hypr_app_taptoauth H 500
  1. Tap the HYPR authentication notification; HYPR Tap to Authenticate.

    If the notification appears on your phone's lock screen, open the HYPR app and unlock your phone to proceed.

    hypr_app_login H 500
  2. Tap Login.

    To cancel, tap Deny.

    You are prompted for biometric authentication (Touch ID or Face ID).

    hypr_app_touchid H 500
  3. Authenticate to the HYPR app using a configured biometric method for your device.

    hypr_app_login_success H 500

After successful multi-factor authentication including Bravura OneAuth, you are logged in to Bravura Safe on your computer.

Note

This procedure must be completed using the Bravura Safe web interface and your mobile device(s).

This topic shows you how to replace a device paired with Bravura OneAuth, either as a planned replacement or after an unplanned loss of the old device.

If you want to replace a mobile device and still have access to the old one, follow these steps.

  1. Transfer all data from your old device to your new device. The exact procedure will vary depending on the operating system.

  2. Install the HYPR app on your new mobile device.

  3. Set up biometric authentication (e.g. Touch ID, Face ID) on your new device.

    This is typically done in device settings. Instructions vary by operating system.

  4. If you have been using an authenticator app (e.g., Google Authenticator, Microsoft Authenticator, etc.) for two-step login (2FA), check that TOTP codes were automatically transferred to the new device.

    If the codes were not automatically transferred to the new device, manually transfer/export authenticator accounts from your old phone to your new phone. Instructions vary based on the authenticator app(s) you are using. Perform this task for each authenticator, as required.

  5. Access the Bravura OneAuth Device Manager to de-register your old device and register your new device:

    You may register/pair multiple devices to your Bravura OneAuth web account.

    See Manage registered (paired) Bravura OneAuth devices.

If you want to replace a mobile device and do not have access to the old one, follow these steps.

  1. Install the HYPR app on your new mobile device.

  2. Set up biometric authentication (e.g. Touch ID, Face ID) on your new device.

    This is typically done in device settings. Instructions vary by operating system.

  3. If you were using an authenticator app(s) for two-step login (2FA) on your old device; for example, Google Authenticator, Microsoft Authenticator, etc.:

    • Install the desired authenticator app(s) on your new device.

    • Set up authenticator accounts/TOTP codes again for use in 2FA.

  4. Log into Bravura Safe using another two-step login method.

    Warning

    If do not have an EMAIL option and any previously used AUTHENTICATOR APP accounts/TOTP codes were not successfully transferred from your OLD device to your NEW device, you will not be able to log in to Bravura Security Fabric . Please contact Bravura Security Support. A manual change to the Bravura Security Fabric database is required to restore Email PIN as an available two-step login (2FA) method, after which you can select EMAIL.

  5. Access the Bravura OneAuth Device Manager to de-register your old device and register your new device:

    You may register/pair multiple devices to your Bravura OneAuth web account.

    See Manage registered (paired) Bravura OneAuth devices.

This topic shows you how to manage mobile devices that are registered/paired to your Bravura OneAuth account.

Access Bravura OneAuth Device Manager

To access Bravura OneAuth Device Manager from Bravura Safe:

  1. Log in to the Bravura Safe web interface.

  2. Click Teams.

  3. Select the Enterprise Team from the Team drop-down (i.e., your main/global company team).

  4. Click the Options tab.

    safe_options_my_team
  5. Click Open Bravura OneAuth device manager.

    A confirmation message appears.

    safe_options_open_device_manager
  6. Click Yes.

    The Bravura OneAuth Device Manager opens in a new browser tab showing all devices currently paired to your Bravura OneAuth account.

safe_options_device_manager

From here you can De-register/unpair a device and Register a new device.

De-register/unpair a device

To de-register/unpair a device:

  1. Click Remove beneath the desired device.

    A confirmation message appears.

  2. Click Remove.

    The selected device is de-registered/unpaired from your Bravura OneAuth account, removed from your Device Manager Login Methods list and removed from MY WEB ACCOUNTS in the Bravura OneAuth app on your mobile device.

    If the removed registered device was your only one, the Device Manager UI displays "No Login Methods Found":

    safe_options_device_manager_login_methods_none
Register a new device

This procedure assumes you have installed the HYPR app on your new mobile device.

  1. From the Bravura OneAuth Device Manager, click Add New Login Method.

    A pop-up appears:

    safe_options_device_manager_add_new_login_method

    Tip

    To see a walk-through of all steps included here, click Walk me through how to add a login method.

  2. To proceed with adding a new login method, click HYPR Mobile App.

    A QR code appears:

    safe_options_device_manager_add_new_login_method2
  3. Follow on-screen instructions to pair your device.

    Note

    If you are having an issue scanning the QR code, click Pair Manually and follow the on-screen instructions:

    safe_options_device_manager_add_new_manual

    Once your mobile device is successfully paired to your Bravura OneAuth Device Manager displays the "Login Method Added Successfully!" message.

    safe_options_device_manager_add_new_login_method3

Once pairing is successful, your new device will appear listed under Login Methods. You may now use this device for passwordless authentication to Bravura Safe using Bravura OneAuth.

Email verification

To set up individual two-step login via email for your safe:

  1. Log in to Bravura Safe via the web interface.

  2. Click the profile menu (your initials) and select Account Settings.

  3. From the ACCOUNT SETTINGS menu, select Security.

  4. Click the Two-step login tab.

    safe_web_ind_two_step_login
  5. Next to the Email option, click Manage.

    safe_web_ind_two_step_login2
  6. Enter your Master password and click Continue.

    Note

    If email verification is already "TURNED ON", click Close to exit and skip the following steps.

    safe_web_ind_two_step_login3
  7. Enter the email address where you want to receive verification codes.

  8. Click Send email.

    safe_web_ind_two_step_login4
  9. Check your inbox for an email message with "Your Two-step Login Verification Code".

  10. Enter the 6-digit code in the dialog box.

  11. Click Turn on.

    A notification message appears.

    safe_web_ind_two_step_login5

    Note

    To disable email verification, click Turn off. A confirmation message appears. Click Yes to proceed. The green check mark is removed from the Email option.

  12. Click Close.

  13. The Email option is enabled when a green check mark appears next to it.

    safe_web_ind_two_step_login6

    Note

    To activate two-step login via Email immediately for each app, log out of all Bravura Safe apps. You will eventually be logged out automatically.

Note

The steps below assume that 'Email' is your highest-priority authentication provider/method that is turned on for your individual safe and that enterprise Two-step login is not enforced. See Using multiple two-step login providers.

To log in to Bravura Safe using your master password and two-step login with email verification:

  1. Open the Bravura Safe application:

    Web interface (shown below): Navigate to your company's Bravura Safe instance URL.

    Desktop or Mobile: Open the Bravura Safe application.

    safe_web_login_email
  2. Enter your Bravura Safe account Email address.

  3. Optionally, select or toggle on Remember email so you do not have to enter it next time.

  4. Click or tap Continue.

    safe_web_login2_w3buttons

    Note

    If your company has configured enterprise single sign-on (SSO), see Log in with SSO.

    To log in using an enabled secondary device without having to enter a master password, see Log in with device.

  5. Enter your Bravura Safe account Master password.

  6. Click Log in with master password (tap Log in for mobile).

    You are prompted to Enter the 6-digit verification code that was emailed to [your configured email].

    safe_web_login_emailver
  7. Check your inbox for the 6-digit verification code.

  8. Enter this code in the field provided (see above).

  9. Optionally, select or toggle on Remember me to not require a second authentication factor for 30 days.

  10. Click or tap Continue to finish logging in.

    Once logged in, you will not need a second authentication factor to Unlock your safe.

    Note

    If your login session times out, you will receive the following notification. Reload/Refresh your browser and log in again.

    safe_web_login_timed_out

When you are logging in using two-step login with email verification and you do not receive the verification code email:

  1. Enter your email address in the provided field.

  2. Click Send verification code email again on the verification pop-up to resend the email.

    safe_web_send_vercode_again

    A notification message appears.

    safe_web_send_vercode_again2

To change individual two-step login via email for your safe:

  1. Log in to Bravura Safe via the web interface.

  2. Click the profile menu (your initials) and select Account Settings.

  3. From the ACCOUNT SETTINGS menu, select Security.

  4. Click the Two-step login tab.

    The Email option is enabled when a green check mark appears next to it.

    safe_web_ind_two_step_login6
  5. Next to the Email option, click Manage.

    safe_web_ind_two_step_login2
  6. Enter your Master password and click Continue.

    safe_web_ind_two_step_login5
  7. Click Turn off.

    A confirmation message appears.

  8. Click Yes to proceed.

    To disable email verification, you can stop here and skip remaining steps. To change your email address, proceed below.

  9. Next to the Email option, click Manage.

    safe_web_ind_two_step_login2
  10. Enter your Master password and click Continue.

    safe_web_ind_two_step_login3
  11. Change the email address where you want to receive verification codes.

  12. Click Send email.

    safe_web_ind_two_step_login4
  13. Check your inbox for an email message with "Your Two-step Login Verification Code".

  14. Enter the 6-digit code in the dialog box.

  15. Click Turn on.

    A notification message appears.

    safe_web_ind_two_step_login5
  16. Click Close.

  17. The Email option is enabled when a green check mark appears next to it.

    safe_web_ind_two_step_login6

    Note

    To activate two-step login via Email with your new email address immediately for each app, log out of all Bravura Safe apps. You will eventually be logged out automatically.

Authenticator app

To enable two-step login for your individual safe using an authenticator app and a secondary (e.g. mobile) device:

  1. Log in to Bravura Safe via the web interface.

  2. Click the profile menu (your initials/avatar) and select Account Settings.

  3. Select Security from the ACCOUNT SETTINGS menu.

  4. Click the Two-step login tab.

    safe_web_ind_two_step_login
  5. Next to the Authenticator app option, click Manage.

    safe_web_ind_twostep_login_authapp
  6. Enter your Master password.

  7. Click Continue.

    safe_web_ind_twostep_login_authapp2
  8. If you do not have an authenticator app on your mobile device, download one.

    Note

    Links are provided on the TWO-STEP LOGIN page, as above.

  9. Open the authenticator app on your device and add a new account.

  10. Scan the provided QR code with your device and authenticator app.

  11. Enter the resulting 6-digit verification code from the app.

  12. Click Turn on.

    A green "TURNED ON" message will indicate that two-step login via Authenticator App has been enabled.

    safe_web_ind_twostep_login_authapp3
  13. Click Close.

  14. Confirm that the Authenticator app option is enabled, as indicated by a green checkbox.

    safe_web_ind_twostep_login_authapp4

    Note

    To activate two-step login immediately for each app, log out of all Bravura Safe apps. You will eventually be logged out automatically.

Note

The steps below assume that 'Authenticator app' is your highest-priority authentication provider/method that is turned on for your individual safe and that enterprise Two-step login is not enforced. See Using multiple two-step login providers .

To log in to Bravura Safe using your master password and two-step login with an authenticator app:

  1. Open the Bravura Safe application:

    Web interface (shown below): Navigate to your company's Bravura Safe instance URL.

    Desktop or Mobile: Open the Bravura Safe application.

    safe_web_login_email
  2. Enter your Bravura Safe account Email address.

  3. Optionally, select or toggle on Remember email so you do not have to enter it next time.

  4. Click or tap Continue.

    safe_web_login2_w3buttons

    Note

    If your company has configured enterprise single sign-on (SSO), see Log in with SSO.

    To log in using an enabled secondary device without having to enter a master password, see Log in with device.

  5. Enter your Bravura Safe account Master password.

  6. Click Log in with master password (tap Log in for mobile).

    You are prompted to Enter the 6-digit verification code from your authenticator app.

    safe_web_login_authapp
  7. Open the authenticator app on your secondary device and find the 6-digit verification code for Bravura Safe.

  8. Enter this code in the field provided.

  9. Optionally, select or toggle on Remember me to not require a second authentication factor for 30 days.

  10. Click or tap Continue to finish logging in.

    Once logged in, you will not need a second authentication factor to Unlock your safe.

    Note

    Typically, verification codes change every 30 seconds. If your login session times out, you will receive the following notification. Reload/Refresh your browser and log in again.

    safe_web_login_timed_out

Using multiple two-step login providers

More than one two-step login method can be used to secure your safe. In this case, when you log in, you are prompted for the highest-priority second-factor authentication method (see below; 1 = highest priority).

  1. Bravura OneAuth

  2. Authenticator app

  3. Email

Example:

If you have both an Authenticator app (priority 2) AND Email (priority 3) providers turned on for your individual safe via Account settings > Security > Two-step login and you log in; because Authenticator app has a higher priority than Email, you will be prompted for a verification code from your Authenticator app as a second authentication factor.

Using the same example, if the Enterprise Team has two-step login enforcement configured using Bravura OneAuth, that will take priority as your second authentication factor.

Note

Any provider/method will still allow you to authenticate.

  • To use a lower-priority method (e.g. Email), click Use another two-step login method and then Select another available (enabled) method.

  • From a Bravura Safe mobile app, tap the vertical ellipsis icon at top right, select Use another two-step login method, select the desired alternative method and proceed with authentication.

Caution

If you typically log in using single sign-on (SSO), do not turn on two-step login via email.