Two-factor authentication

Why two-factor authentication matters

We strive to provide you with the necessary tools to keep your account secure.

We have a split responsibility model when it comes to security, we secure our application and infrastructure, and it is your responsibility to ensure the safety of your account credentials and account security. Two-factor authentication (or 2FA) is the best way to ensure security.

Without two-factor authentication, should your account password be compromised, your account could be subject to unauthorized access and could cause you to be negatively impacted:

  • credits or credit card charges as a result of emails sent from your account
  • extraction of subscriber data
  • privacy regulation implications (like GDPR)
  • brand and reputation impact from unsolicited emails that appear to come from you

By enabling two-factor authentication, your identity is verified twice using two authentication methods - a password as well as a time-based one-time password (TOTP) from your phone - which are then required in order to log in and perform key functions. These multiple layers of protection will keep your account secure.

Enabling two-factor authentication

We support multi-factor authentication in your account in two ways:

  1. Full-access users can choose to apply a security policy requiring users to set up 2FA as a condition for account access. See section Setting an account’s 2FA policy for more information.
  2. Users for whom 2FA remains optional can elect to set up an authenticator for their own login.

Setting an account’s 2FA policy

Permission required to use this feature: administrator

Rolling out a policy change

Implementing a change in security policy can be surprising and disruptive for your colleagues. In order to minimize discomfort to the people using your shared account, and keep your own support load to a minimum, we recommend the following roll-out strategy:

  1. Choose a date for when you’ll be applying the policy.
  2. Communicate with your colleagues (for example via email and/or chat) to inform them of the coming change and explain the reasons why.
  3. Include a link to the instructions for personally enabling two-factor authentication (you may wish to consider customizing these and linking to your own version if you have a preferred authenticator).
  4. Make the change on the scheduled date.
  5. Be ready to support colleagues who didn’t follow the advice in advance.
Setting the policy

You can choose from one of three policy options:

  • Optional for everyone – This is the default setting. Choosing this will not change anybody’s personal authenticator settings, but will remove the requirement for new and existing users.
  • Required for all administrators 2FA is required of those users with full access to every feature and setting. Any people with limited access are still free to make their own decision.
  • Required for everyone – The most secure setting. Everybody who can login to the account, regardless of permissions, is required to set up an authenticator.

Device pinning is a feature that will show users an option labeled "Don't ask again on this device for 30 days" on the two-factor authentication code entry screen. The feature can be disabled when the policy is set to "Required for all administrators" or "Required for everyone".

Note that to make any change to an account-wide 2FA policy, you are first required to personally enable an authenticator for your own login.

When you’re ready to make the change:

  1. In your account, click your profile image at the top right, then select Account settings.
  2. In the “Security details and settings” section, click Edit.
  3. Choose the required policy setting and device pinning option (if available), then click Save.
  4. If you select "Required for all people with full access" or "Required for everyone," you will be presented with an option to "Log out of all devices". Check the box to immediately log out everyone affected by the policy change and require them to set up 2FA before they can log back in.
  5. You will be required to confirm your password and enter an authentication code, and check a box to ensure you understand the number of people who will be impacted by the change.
  6. Finally click Require 2FA (or Make 2FA optional if you have chosen that settings).

Once the change is saved, it will affect users in the following ways:

  • Existing users who match the policy setting will be required to set up an authenticator next time they log in. Any users who fail to do so within 30 days of the policy change are locked out. However, an account administrator is able to reset the authenticator setup for an additional 12 hours.
  • New invited users will have to set up an authenticator as the final step of accepting their invitation.

Two-factor authentication is not required when logging in via embedded session.

Reset authentication setup

If a person in a client has failed to set up their authenticator within 30 days of a policy change that affects them, they will be locked out of their account. You are able to give them an additional 12 hours by doing the following:

  1. Click Clients in the top navigation, then select the relevant client.
  2. Open the Settings menu near the top right and click on People.
  3. Click Reset setup next to the person's name you wish to reset setup for.
  4. Enter your password and verification code and then click Confirm.

If an administrator has failed to set up their authentication in time, you can give them an additional 12 hours by doing the following:

  1. Click your profile image at the top right, then select Account settings.
  2. Below “Administrators in your account”, click Reset setup next to the administrator’s name you wish to reset setup for.

The user’s status will now be set back to a waiting status and they will have another 12 hours to set up two-factor authentication. 

  • "Pending Setup" for a regular user
  • "Waiting for 2FA to be set up" for an administrator. 

Enable your own two-factor authentication

To enable two-factor authentication for your login:

  1. In your Campaign Monitor account, click your profile image at the top right, then select Account settings.
  2. Click Administrators in the left sidebar.
  3. Click to open the three-dot icon for your name, then choose Manage 2FA setup.
  4. On the next screen, click Enable two-factor authentication, then follow the on-screen instructions.

You will be prompted to install one of several authenticator apps on your phone. Note that these are only recommendations. Most authenticator apps will be sufficient, and if your organization has a standard or required application, we recommend testing that first.

Setting up an authenticator as a requirement

If you find that you are required to set up an authenticator before you can log in to your account, this is because an administrator has made a policy decision to protect your account against unauthorized access. If you are unsure about this, please reach out to your administrator(s) and ask them for guidance.

Setting up two-factor authentication will normally only take a couple of minutes, and may involve installing an authenticator application on your smartphone or device. In most cases it will be ok to use any authenticator you have already installed. See section Enable two-factor authentication for your login for more information.

Log out from all other devices

If you want to log out from all other devices except the current one, check the "Log out from all other devices" box during the two-factor authentication setup.

Logging out from all other devices enhances your account's security by:

  • Terminating potential unauthorized access – Ensures that any sessions on other devices, especially those you no longer use or don't recognize, are closed.
  • Protecting against public or shared device risks – Reduces the risk of your account being accessed from public or shared devices you might have used previously.
  • Ensuring exclusive session activity – Keeps your session active only on the current device, reducing the risk of unauthorized changes or access to your data and settings.

Using two-factor authentication

Once two-factor authentication is set up in your account, you will be prompted to add the access code from your authenticator app each time you log in.

You will need to get a new code from your authenticator app with each login, as the access code rotates every 30 seconds.

To ensure full security of your account, you will be required to add your 2FA access code each time you:

  • Log in (once every 24 hours), unless you have chosen not to ask again for 30 days
  • Change your password
  • Add someone to your account
  • Remove someone from your account
  • Enable 2FA in your account
  • Disable 2FA in your account

Pinning the device

When you have two-factor authentication enabled and attempt to log in to your account, you will see an option labeled "Don't ask again on this device for 30 days" on the two-factor authentication code entry screen. This option is ticked by default. Selecting this option will remember your current browser, allowing you to bypass the two-factor authentication code entry for the next 30 days when using this browser.

Additional information:

  • Multiple browsers and devices – Pinning is specific to each browser. If you use multiple browsers or devices, you will need to pin each one separately.
  • Incognito/private browsing – If you use incognito or private browsing modes, the pinning option will not work, and you will be prompted to enter your two-factor authentication code.
  • Security recommendations – For enhanced security, only pin browsers on personal devices. Avoid pinning browsers on public or shared devices to protect your account.
Unpinning the device

If you unintentionally leave the "Don't ask again on this device for 30 days" option ticked and wish to unpin the browser before the end of the 30 days, you have a couple of options:

  1. Clear browser cookies – Clearing your browser cookies will remove the device pinning. The next time you log in, you will be prompted to enter your two-factor authentication code for the current browser. 
  2. Reset your two-factor authentication (2FA) – Resetting your 2FA will unpin all previously pinned browsers. The next time you log in, you will be prompted to enter your two-factor authentication code for any browser.

Disabling two-factor authentication

To disable two-factor authentication for your login:

  1. Click your profile image at the top right, then select Account settings.
  2. Click Administrators in the left sidebar.
  3. Click to open the three-dot icon for your name, then choose Manage 2FA setup.
  4. On the next screen, click Disable two-factor authentication, then follow the on-screen instructions.
  5. Delete the relevant entry from the Authenticator app on your phone.

If two-factor authentication is required as part of a security policy it will not be possible to turn off two-factor authentication.

Lost authenticator or phone

If you've lost your phone or don't have access to Authenticator, and therefore can no longer access your account, you can remove two-factor authentication. To do so:

  1. Go to the login screen for your account, enter your username and password, then go to the next step.
  2. Click Lost your authenticator, enter your details, then click Send me an email.
  3. When you receive the email, follow the instructions to disable two-factor authentication. If you don't see the email, check your spam folder.
  4. Log into your account.
  5. Enable two-factor authentication again as soon as possible.