What is MFA, and why do I need it?
Multi-factor authentication (MFA) adds a second layer of security beyond just your username and password. After MFA is set up, logging in requires two things: something you know (your password) and something you have (a 6-digit code generated by an app on your phone).
Biotics 6 requires MFA for every user. This guide walks through everything you need to do — including installing an authenticator app for the first time if you've never used one before.
Note: If you've never set up an authenticator app before, that's completely fine. Section 1 below walks through it from scratch — you don't need any prior experience. |
1. Setting Up an Authenticator App on Your Phone
Before you can log into Biotics 6, you'll need an authenticator app installed on your phone. This is a free app that generates a new 6-digit security code every 30 seconds.
Which app should I use?
We recommend Google Authenticator — it's free, simple, and works well. Other authenticator apps (such as Microsoft Authenticator, Authy, or Duo Mobile) work too, and are all set up in a very similar way. Pick whichever you're most comfortable with; the steps below apply to any of them.
Installing Google Authenticator
- Open the App Store (iPhone) or Google Play Store (Android) on your phone.
- Search for “Google Authenticator.”
- Tap Install (or Get), and wait for it to finish downloading.
- Open the app once it's installed. No account or sign-in is required to use it.
That's it — the app is now ready and waiting. You won't need to do anything else in the app until you get to the MFA setup step in Section 2, where Biotics 6 will show you a QR code to scan.
Note: Keep your phone handy when you get to Section 2 — you'll need to scan a QR code with this app as part of your first login. |
2. Instructions for Existing Users (First-Time Login to Biotics 6)
This is what all existing users must do before logging into Biotics 6 for the first time.
- Go to the Biotics login screen and select Forgot Password. Enter your email address.
- You will receive a welcome email containing a password reset code. Enter that code into the password reset form.
- Once your password is reset, you will be prompted to set up MFA using your phone:
- You will need an authenticator app installed on your phone (see Section 1 above if you haven't done this yet).
- Follow the on-screen instructions to scan the QR code with your authenticator app, then enter the 6-digit code the app generates into the Biotics 6 form.
- You will then be logged in.
From now on, every time you log in you'll enter your email and password as usual, then open your authenticator app and enter the current 6-digit code.
3. Instructions for Adding a New User
- Log into Biotics and go to the Users Management page, then select Create User.
- As long as the email address entered for the user is valid, that user will receive a welcome message.
- The new user must use Forgot Password the first time they log in, in order to “claim” their account (see Section 2 above for the full first-time login steps).
4. Instructions for Re-Sending a Welcome Message
Use this if something went wrong with a user's initial MFA setup attempt, or if they never received their welcome email.
- Log into Biotics and go to the Users Management page, then click the Edit action for the user.
- Disable the Active checkbox and click Save.
- Re-enable the Active checkbox and click Save. This will send the user a new welcome message.
Note: The welcome email tells the user to log in with their existing username and password. If the user hasn't set up MFA yet, they need to use Forgot Password first — they should follow the Section 2 instructions above (“Instructions for Existing Users”). If they try to log in with just their Biotics password without having set up MFA, they will get an error message. |
5. Instructions for Changing a User's Email Address
- Log into Biotics, go to the Users Management page, and disable the current user's record.
- Select Create User to create a new user record with the updated email address. This will send a welcome message to the new address.
Note: The new user record will need a new username, since the old username is tied to the old email address. |
6. What if I don't have a smartphone?
If you don't have a smartphone, the following options may work for you. Unfortunately we don't have the ability to implement other MFA solutions at this time.
Solution 1: Corporate Browser Extensions (Easiest)
If these users are on corporate laptops, they can use a secure web browser extension to process the MFA token. They do not need a phone at all.
- How it works: When the user reaches your application's MFA registration screen, they click the browser extension. Instead of scanning a QR code with a phone, they click "Enter key manually," copy the text string provided by AWS Cognito, and save it in the extension. The extension will generate the 6-digit code directly in their browser tab.
- Top Tools:
- Authenticator on the Chrome, Firefox and Edge Add-on: https://authenticator.cc/ A highly popular, open-source browser extension that encrypts tokens locally and functions entirely offline. This extension is verified to work on Chrome, Edge, and Firefox
- This Chrome Extension has been verified to work, but does cost $20/year, The documentation suggests it does support Edge was well, but has not been tested in Edge: https://www.typingdna.com/authenticator
- This is a suggested Edge Extension but has not been tested: https://microsoftedge.microsoft.com/addons/detail/authenticator-2fa-client/ocglkepbibnalbgmbachknglpdipeoio
Solution 2: Corporate Desktop Applications
If browser extensions are blocked by your company IT policy, the users can install a standalone desktop application on their work computers to generate the codes.
- How it works: Just like the browser extension, the user copies the raw text secret key from your web application's setup page and pastes it into the desktop software.
- Top Tools:
- Bitwarden Desktop App: If your company uses Bitwarden for enterprise password management, the desktop client can natively store the TOTP seed and display the 6-digit codes.
- KeePassXC: A free, local, open-source password manager for Windows, macOS, and Linux that has a built-in cryptographic TOTP generator.
Solution 3: Hardware TOTP Tokens (Zero-Software Option)
If these users work in a highly secure environment where browser extensions and local software are restricted, you can provide them with a physical keychain fob.
- How it works: You purchase a programmable hardware token. An IT administrator plugs the token into a computer once via USB, copies the secret text string from the user's Cognito MFA setup screen, and flashes it onto the fob using the manufacturer's helper software. From then on, the employee simply presses a button on the plastic fob, and it displays the 6-digit code on an LCD screen.
- Compatible Hardware:
- Feitian Technologies OTP c200 OATH Time-Based 2FA Token H27: A budget-friendly, standalone OATH-compliant token that functions entirely offline.
- Token2 programmable hardware tokens: Specifically designed to act as drop-in replacements for mobile authenticator apps by accepting standard text-based seed keys.
Solution 4: Standalone Tablets or Disconnected Mobile Devices
If these users have an iPad, an Android tablet, or an old personal smartphone that they are willing to keep at their desk strictly for work authentication, they can use it as a dedicated MFA device.
- How it works: The user connects the tablet or old phone to Wi-Fi just long enough to download a standard authenticator app from the App Store or Google Play Store. During enrollment, they use the device's camera to scan your web application's QR code. Once the account is linked, they can turn off Wi-Fi completely. The app will continue to generate valid, accurate 6-digit codes entirely offline.
- Top Tools:
- Google Authenticator / Microsoft Authenticator: Available for both iPadOS and Android tablets. They run completely local cryptographic calculations.
- Twilio Authy: Excellent if they want to sync codes across multiple non-phone devices (like an iPad and a desktop client simultaneously).
- Important Caveat: Because TOTP codes rely heavily on time-synchronization, the tablet or old phone must have its internal clock set accurately. If the device sits powered off for months and its clock drifts by more than a minute, the generated codes will fail until the device is briefly reconnected to Wi-Fi to sync its system time.
Need Help?
If you run into any issues during setup — a QR code that won't scan, a welcome email that never arrived, or an error message during login — contact the Help Desk and we'll help get you back in.