Account security
Protect a VMOTEK staff account with two-step verification
A password or Google identity is the first proof that a person owns a VMOTEK staff identity. Two-step verification adds a time-limited code held on that person's device. VMOTEK supports standards-based TOTP authenticator apps and one-time recovery codes. The encrypted authenticator secret is never returned after setup, recovery codes are stored only as hashes, and every enrollment, challenge, recovery-code use, reset and policy change creates accountable security evidence.
Written by the VMOTEK Product Team · Updated August 13, 2026
01
1. Open your personal Account security page
Sign in to the repair application. Select your initials in the upper-right corner and choose Account security. Every staff member manages their own authenticator, recovery codes and personal security activity here; an owner should not share one device or one login among several employees. The page shows whether the authenticator is enabled, how many unused recovery codes remain and recent successful or failed security events. Company-wide enforcement is intentionally administered elsewhere under Settings so personal account actions and company policy are not confused.
- Personal navigation: user initials → Account security.
- Use Change password for the password itself; use Account security for the second factor.
- Administrative navigation: Settings → Communications & Access → Security & Access.
02
2. Start authenticator enrollment
Choose Set up authenticator. VMOTEK creates a unique secret and displays both a QR code and manual setup key. Open Google Authenticator, Microsoft Authenticator, Authy, 1Password or another RFC 6238-compatible app. Add an account by scanning the QR code. If camera access is unavailable, enter the displayed setup key manually and select a time-based, six-digit code with a 30-second period. Do not paste the key into email, chat or a support ticket.
03
3. Confirm the device
Enter the current six-digit value from the authenticator and choose Confirm. Enrollment is not active until this confirmation succeeds. Codes change every 30 seconds and VMOTEK accepts only a small clock-drift window. A code already used for a successful challenge cannot be replayed. If a valid-looking code fails, confirm the phone has automatic date and time enabled, wait for the next code and try once more.
04
4. Save recovery codes
After confirmation, VMOTEK displays ten recovery codes exactly once. Copy or print them and store them in the organization's approved password manager or secure physical location. Each code works once. VMOTEK stores only a one-way hash, so support cannot retrieve the original values. Generating a replacement set immediately invalidates every prior unused code. Never store recovery codes beside the password in an unsecured spreadsheet.
05
5. Sign in with MFA
At sign-in, enter the password or continue with Google as usual. When Two-step verification appears, enter the current authenticator value. If the device is unavailable, enter one unused recovery code instead. Five failed attempts temporarily lock challenges to slow guessing. Successful verification is remembered briefly for sensitive account actions, but it does not create a permanent trusted-browser bypass.
06
6. Configure company enforcement in Settings
An owner or administrator opens the Settings gear, selects the Company view, finds Communications & Access and opens Security & Access. In Company MFA policy, Optional lets each employee decide. Owners and administrators directs privileged staff to enroll after sign-in. All staff applies the requirement to every staff identity. A covered user who has not enrolled is sent to Account security and cannot use operational APIs until setup is complete. Roll out enforcement deliberately: notify employees, require individual accounts, confirm device availability and define who may authorize a reset. Fleet portal customers use separate portal identities and are not included in this staff policy.
- Navigation: Settings gear → Company → Communications & Access → Security & Access.
- Start with Owners and administrators when introducing MFA to an existing team.
- After affected users enroll successfully, consider expanding the policy to All staff.
- Changing MFA policy does not change a user’s role or shop access.
07
7. Recover or administratively reset access
A staff member should first use an unused recovery code on the normal Two-step verification screen. If the device and every recovery code are lost, an independently verified administrator or VMOTEK support procedure is required. The administrator opens Settings → Communications & Access → Security & Access, enters the staff email and a meaningful reset reason, then confirms the action. The acting administrator must have completed recent MFA verification. VMOTEK records the target, actor, time and reason, disables the old factor and requires the affected user to enroll again when company policy applies. Never reset MFA solely because someone knows an email address or can answer information visible on an invoice.
08
8. Review evidence and respond
Recent security activity shows enrollments, successful challenges, failed codes, recovery-code use, regenerated codes, policy changes, resets and disables. Review unexpected failures with the employee, confirm the source device and rotate the password when compromise is plausible. IP address and browser details are supporting evidence, not identity proof by themselves. Preserve relevant event IDs when contacting support.
09
9. Operational rollout checklist
Start with owners and administrators, test one recovery code, then expand to managers and staff. Confirm every person has an individual VMOTEK account and that former employees are deactivated. Include MFA recovery ownership in the shop's management handoff procedure. After rollout, sign in with a test administrator, advisor and technician; verify MFA appears where required and that no role or shop permission changes merely because MFA was enabled.
- Confirm the authenticator code before leaving setup.
- Store recovery codes outside the employee's device.
- Record who may approve an administrative reset.
- Review recent security activity after a reset or suspicious login.
- Do not photograph QR codes for training material or support.
Related product areas
Understand the capability behind the task
Continue to the applicable platform page for workflow behavior, role differences and connected operating consequences.
Ready to move forward?
Need help with your configuration?
Existing customers should use in-product support for account-aware assistance. Evaluation teams can contact us to discuss requirements.