Skip to main content
In addition to the email login code that all users receive, team members must enter a time-based one-time password generated by an authenticator app on their mobile device when MFA is enabled. Even if someone intercepts a login code, they cannot access PastaHR without physical access to the registered device.

Enabling MFA for Your Organisation

MFA is not enabled by default. To turn it on for your PastaHR workspace, an Admin must contact the PastaHR support team: Email: support@pastahr.com Include your company name and the workspace you’d like MFA enabled for.
Once MFA is enabled for your organisation, all users will be required to complete MFA setup on their next login. Let your team know ahead of time before you request activation, so no one is caught off guard.

First-Time MFA Setup for Users

When a user logs in for the first time after MFA has been enabled, or when a new user accepts an invitation after MFA is already active, they are automatically guided through the setup process.
1

Install an authenticator app

Before setup, the user needs one of the supported authenticator apps on their mobile device.

Google Authenticator

Microsoft Authenticator

2

Scan the QR code

During the login or account acceptance flow, PastaHR displays a QR code on screen. The user opens their authenticator app, taps Add account (or the + button), and selects Scan a QR code. They then point their camera at the QR code shown by PastaHR.
3

Enter the one-time password

After scanning, the authenticator app immediately begins generating six-digit codes for the PastaHR account. The user enters the current code into the PastaHR confirmation field to verify the setup was successful.
4

Setup complete

MFA is now linked to the user’s account. On every future login, they will be asked for a code from their authenticator app after the email login code.
Advise your team members to enable cloud backup in their authenticator app (available in Google Authenticator and Microsoft Authenticator). This way, if they lose or replace their phone, they can restore their MFA accounts without being locked out of PastaHR.

Recovering a Locked Account

If a user no longer has access to their authenticator app and can’t generate an MFA code, they can’t complete the login flow. An Admin can reset MFA for any team member directly from the Settings panel.
1

Go to Settings → Members

Log in to PastaHR as an Admin and navigate to Settings in the left sidebar, then click Members.
2

Open the actions menu for the affected user

Find the locked-out team member and click the three-dot menu (⋮) next to their name.
3

Select Reset MFA

Select Reset MFA from the menu.
4

User re-enrolls on next login

The next time that person logs in, they will be asked to set up MFA again from scratch.
If you are the only Admin and you yourself are locked out, contact support@pastahr.com for assistance.