DraftIndicative placeholder for the section owner — amend, replace, or confirm as the first definitive version.
Doc owner: Security Officer
Authenticator
Multi-factor authentication is mandatory wherever supported — see POL-DIG-004 Password Policy. This guide covers picking and using a TOTP authenticator app.
Supported apps
Allied does not mandate a single vendor. Pick one of these:
Whatever you pick must support TOTP (time-based one-time passwords) and let you back up or export accounts securely.
Quick start (iOS and Android)
- Install your chosen authenticator from the App Store or Google Play.
- Open the app and tap + (or Add Account).
- Scan the QR code shown by the service you are securing (e.g. the Allied SSO portal).
- Enter the 6-digit code from the app to confirm set-up.
- Save any backup or recovery codes the service offers — store them offline.
Desktop (optional)
Authy offers a desktop client for Windows and macOS:
- Download Authy for Desktop.
- Sign in with your phone number.
- Enable multi-device only if you actually need to sync across devices.
- Add accounts by scanning QR codes from your phone or entering the secret manually.
Best practices
- Backup and recovery — store recovery codes offline (e.g. paper in a locked drawer).
- App lock — enable biometrics or PIN-lock on the authenticator app.
- Device security — treat the authenticator like a password: strong passcode, encryption on.
- Multi-device sync (Authy only) — use sparingly; disable if you do not need it.
- Account hygiene — remove tokens for services you no longer use.
- Updates — install app updates promptly.