What is MFA and How Does It Work?

To enhance the security of your data and accounts, Prohire Software is introducing Multi-Factor Authentication (MFA) for all users.

MFA helps protect against unauthorised access by requiring users to verify their identity through two steps: something they know (their password) and something they have (a second verification method). This significantly reduces the risk of account compromise — even if a password is stolen.

When logging into Prohire Software, users will:

  1. Enter their username and password.

  2. Be prompted to complete a second verification step using one of the available MFA methods.


Authentication Methods

Preferred Method: Authenticator App (TOTP)

This is the most secure and recommended option. A Time-Based One-Time Password (TOTP) is generated via an app on your phone and changes every 30 seconds.

Supported apps include:

  • Google Authenticator
  • Microsoft Authenticator
  • Aegis
  • 2FAS

These apps do not require internet or mobile signal — just access to your phone.

Alternative Method: Email Verification

For users unable or unwilling to use a mobile device, MFA can be completed via a one-time code sent to a secure email address. This method will be available to all users; however, we encourage the use of an authenticator app whenever possible.


Rollout Plan

To ensure a smooth transition, we are implementing MFA in phases:

  • The functionality will be released in a disabled state by default, allowing users to enable it at their discretion when ready.
  • A grace period will be provided to allow all users to sign up before MFA becomes mandatory.

You will receive:

  • Email communications with instructions
  • 1:1 support via call, if needed

Key Features

  • “Remember Me” Functionality:
    Once authenticated, users can stay logged in for up to 14 days on trusted devices — reducing disruption while maintaining security.

  • Backup Options:
    If their phone is unavailable, they can use email to complete the login.

  • New Hire Companies:
    All new clients will be required to use MFA from day one.

Author: Molly Curtis

12th Aug 2025