Account security
Change your password, turn on two-factor authentication, and see or sign out the devices currently signed in to your account.
Your account security page holds three cards: Change password, Two-factor authentication, and Active sessions. Open it by clicking your avatar at the bottom of the sidebar (the user menu's header row opens My account), then switching to the Security tab, or go directly to /dashboard/account/security.
A separate page from Your settings
This page is for password and session security. Your name, avatar, language, time zone, and theme live on Your settings instead, and which product emails you get on Email notifications. A tab strip above the page lets you switch between the three directly, without going back through the user menu.
Change your password
Use this when you know your current password and just want to set a new one: you don't need to go through "forgot password" for that.
Click your avatar at the bottom of the sidebar to open My account, then switch to the Security tab.
In the Change password card, enter your Current password, then your New password and Confirm new password.
Click Change password. On success, you stay signed in on this device, and every other device currently signed in to your account is signed out.
Your current password is checked before anything changes. Get it wrong and nothing is updated. The new password follows the same policy as signing up or resetting a password: at least 10 characters, and rejected if it's turned up in a known data breach, even if it's long enough. See Signing in and out.
If you use Google, Microsoft, or SSO
This card can't tell a wrong password apart from an account that has no password at all (a Google, Microsoft, or SSO account). If your current password is rejected and you don't remember setting one, that's likely why: there's nothing to change here.
Turn on two-factor authentication
Two-factor authentication (2FA) adds a code from an authenticator app to your sign-in, on top of your password. It's your own choice: turning it on protects only your account, and there's no setting for an organization admin to require it for anyone else.
If your organization signs you in through SSO
Turning two-factor on works whether you signed in with a password or with Google or Microsoft. The one exception is enterprise SSO: there the card offers no Enable button, because your organization's identity provider is what applies its own multi-factor policy, and this page can't add one on top of it. Ask whoever administers it.
Click your avatar at the bottom of the sidebar to open My account, then switch to the Security tab.
In the Two-factor authentication card, click Enable two-factor authentication.
Scan the QR code with an authenticator app (Google Authenticator, 1Password, Authy, or similar). If you'd rather not scan, click Can't scan the code? to reveal a manual-entry key you can copy instead.
Enter the 6-digit code your authenticator app generates, then click Verify and enable.
Once enabled, the sign-in screen asks for this code every time you sign in, including when you sign in with Google or Microsoft. The code is tied to your account, not to one way of signing in, so linking a Google identity to an account that already has two-factor on doesn't give you a way around it. Five incorrect confirmation codes in a row (or clicking Cancel during setup) cancels the enrollment; nothing is turned on until a code is confirmed.
Turn off two-factor authentication
Disabling is available whenever two-factor is on, however you signed in: password, Google, Microsoft, or SSO. It's also your only way out if you lose your authenticator app, so do it while you're still signed in: there's no dashboard control for an admin or a teammate to remove someone else's two-factor, and no backup codes.
Not from a support session
If an iAdvize support engineer is viewing your account as you, neither Enable nor Disable is offered. The card reports whether two-factor is on and stops there. Removing a factor on your behalf is done through our identity provider instead, so that it's a deliberate, recorded action rather than a click inside a session that looks like yours.
In the Two-factor authentication card, click Disable, then Disable again in the confirmation dialog. That's it: the factor is removed the moment you confirm: no authenticator code, no password, and no signing in again first. You're no longer asked for a code at sign-in.
To protect the account again, enroll a new factor from the same card, available whichever way you signed in, unless your organization uses enterprise SSO (see above).
If the removal fails, the card shows "Could not disable two-factor authentication. Please try again." and two-factor stays on.
You get an email whenever two-factor is turned off
Because nothing else stands in the way of the Disable button, we tell you after the fact instead. Every time a factor is removed from your account, we email your account's address, subject "Two-factor authentication was turned off". It confirms that signing in no longer asks for a code from your authenticator app, and says: if you did this, nothing else is needed; if you didn't, turn it back on now and change your password. A Review your security settings link takes you straight back to this security page.
The email is a heads-up, not an approval step: two-factor is already off by the time it's sent, and it's sent on a best-effort basis. If it never arrives, two-factor is off regardless, so check this page rather than your inbox to know where you stand.
View and manage active sessions
Click your avatar at the bottom of the sidebar to open My account, then switch to the Security tab.
In the Active sessions card, review the table. Each row shows a human-readable device name (for example "Chrome on macOS", parsed from the session's browser) and when that session started. Hover (or focus) the device name to see its IP address, how it signed in, and when the session expires, shown as No fixed expiry if it doesn't have one. The session you're currently reading this on is marked This device.
When you have more sessions than fit on one page, Previous and Next controls appear below the table. The controls only show up once there's more than one page.
Sign out of one session
Click Sign out on any row and confirm. Signing out a session ends it immediately, wherever it is. Signing out your own current session signs you out of the dashboard right away, the same as using Log out in the user menu.
Sign out of every other session
When you have more than one active session, a Sign out of all other devices button appears above the list. Confirming it signs out every session except the one you're on: your own device stays signed in.
This also happens automatically when you change your password
Changing your password (above) signs out every other session as a side effect. This button is the same action, on demand, without also having to set a new password.
Languages and localization
Choose the dashboard's regional locale, understand the difference between the translation language and the date/number format, and what the setting does and does not change.
Email notifications
Turn on the weekly product update or the daily changelog email, see what each one contains, and unsubscribe from either without losing the other.