Skip to main content

Overview

Two-factor authentication adds a second step when you sign in. As well as your password, you enter a short code from an app on your phone. The two steps are deliberately different kinds of thing: That combination is what makes it strong. A password can be guessed, reused across sites, exposed in a breach of some service that has nothing to do with Pear, or handed over to a convincing email. All of those happen at a distance, to thousands of people at a time. Taking your phone out of your pocket does not scale the same way. So with two-factor authentication switched on, someone who has your password still cannot reach your account. They would need your phone as well, and they are not in the room. You will find it in Settings, under Two-factor authentication. Open Settings by clicking your name at the bottom of the left menu.

Why we keep bringing it up

Multi-factor authentication is one of the eight mitigation strategies in the Essential Eight, the baseline the Australian Signals Directorate recommends to every organisation. It is on that list for a simple reason. Of all the things you can do to protect an account, requiring a second factor stops the largest share of real attacks for the least effort. Stolen and reused passwords are how most account compromises begin, and a second factor ends that route on its own. If your organisation is working towards the Essential Eight, or answering questions about it from an insurer, an auditor or a customer, turning this on across your team is one of the clearest pieces of evidence you can point to.

Is it required?

Not yet. Today it is opt-in, and you decide whether to turn it on.
This is changing. Pear Australia will be making two-factor authentication mandatory for signing in to the Pear Portal in the coming months. When that happens, accounts that do not already have it will be asked to set it up before they can carry on using the portal.We would much rather you turned it on now, at a moment that suits you, with your phone to hand, than met it for the first time on a busy Monday morning with a waiting room full of people.
In the meantime, Pear Australia strongly recommends it on every account, and particularly on accounts that can see information about patients, customers or staff. Call recordings, transcripts, faxes and contact details are all personal information, and the people they belong to did not choose your password. A second step is the single most effective thing you can do to keep that information where it belongs. If your practice or business handles health information, your own privacy obligations are a good reason to turn it on across the team now rather than leaving it to individuals.
Turning it on takes about two minutes and needs nothing but your phone. See Turn on two-factor authentication.

How signing in works once it is on

  1. Enter your email and password as usual.
  2. Enter the six-digit code from your authenticator app.
  3. You are signed in.
Codes change every thirty seconds, so you always read a fresh one from the app rather than remembering it. You can tick Trust this device for 30 days when you enter a code. On that browser and computer you will not be asked again for a month. Anywhere else, including a new phone or a colleague’s machine, still asks every time. Leave it unticked on shared or public computers.

Turn on two-factor authentication

You will need an authenticator app on your phone. You may well already have one, since the same apps are used for Microsoft 365, banking and plenty of other services. If you do, use it. There is no need for a second one. If you do not have one yet, either of these is free and takes a minute to install: Authy and the authenticator built into 1Password work equally well. Any app that supports standard authenticator codes will do, so use whichever you already trust.
If you already use Microsoft Authenticator for your work email, adding the Pear Portal to it keeps everything in one place.
Step 1. Go to Settings and find Two-factor authentication, then click Set up two-factor authentication. Step 2. Confirm your password. This is to make sure it is you setting this up and not someone who has wandered up to your unlocked computer.
Confirm your password dialog with a password field, Cancel and Continue
Step 3. Scan the QR code with your authenticator app.
Scan the QR code dialog showing a QR code, a code to enter manually, a six-digit code field, and Verify and turn on
If you cannot scan it, for example because you are reading this on the same phone that has the app, type the code under Or enter this code manually into your app instead. It does exactly the same job. Step 4. Your app will now show a six-digit code that changes every thirty seconds. Type the one showing right now into the 6-digit code box and click Verify and turn on.
If it says the code is wrong, you have most likely typed one that has just expired. Wait for the app to show a fresh code and try that one.
Step 5. Save your backup codes. Read the section below first, because this screen appears only once.

Backup codes

When you turn two-factor authentication on, you are given a set of one-time backup codes. Each one signs you in once, in place of a code from your app. They exist for the day your phone is lost, stolen, wiped or simply flat, so keep them somewhere you can reach without that phone. A password manager is ideal. A note in your desk drawer is better than nothing. A screenshot on the phone itself defeats the purpose.
Backup codes are shown once, when you first turn two-factor authentication on. They cannot be shown again afterwards. Click Download codes and tick the box to confirm you have saved them before you close that screen.
If you use some of your codes, or you are not sure they are still private, click Regenerate backup codes in Settings. You will confirm your password, and a fresh set replaces the old one. The old codes stop working immediately.

If you cannot reach your authenticator app

By default, you can ask for a code by email instead. On the sign-in screen, choose to have a code emailed to you and enter that. This is convenient, and for most people it is the right setting. It is also the weaker of the two routes, because anyone who can read your email can then complete your sign-in. If you would rather your account depended only on your phone and your backup codes, turn off Allow a login code by email if I lose my authenticator in Settings. Turning it off makes your account stronger. It also means that if you lose both your phone and your backup codes, you will need to contact Pear support to get back in.

Turn off two-factor authentication

  1. Go to Settings and find Two-factor authentication.
  2. Click Turn off.
  3. Confirm your password.
You are signed out straight away, and you sign back in with the new setting in force. This is deliberate. Changing how your account is protected should take effect immediately rather than waiting for your current session to end. You can turn it back on at any time. You will be given a new set of backup codes when you do, and any previous ones stop working.
Worth knowing before you turn it off: two-factor authentication is becoming mandatory for the Pear Portal in the coming months. If you are switching it off to move to a new phone, it is quicker to turn it off and straight back on with the new device than to leave it off and set it up again later.

If you are locked out

Work through these in order.
  1. Use one of your backup codes.
  2. If email codes are still enabled on your account, ask for a code by email.
  3. Contact Pear support. We can clear two-factor authentication from your account so you can sign in with your password and set it up again. You will get an email confirming this was done, so if one ever arrives unexpectedly, tell us straight away.
If you enter the wrong code several times in a row, sign-in is paused for about fifteen minutes. Wait it out and try again, or use a backup code. Nothing is deleted and your account is not closed.
Codes from an authenticator app depend on your phone’s clock. If your codes are being rejected and you are certain they are correct, check that the date and time on your phone are set automatically.

The occasional reminder

If you have not turned two-factor authentication on, a prompt about it appears from time to time.
Turn on two-factor authentication prompt with an acknowledgement checkbox, Set up now, Remind me later and Don't ask again
You have three choices: Closing the prompt with the X, or pressing Escape, counts as Remind me later. Nothing is decided by accident.

Why there is a tick box

Don’t ask again only becomes clickable once you tick I understand my account is less protected without it. That is not us being awkward. Turning off a security prompt for good is a real decision, and it should be a deliberate one rather than the fastest way to clear something off your screen. Ticking the box is you saying you have understood the trade and made a choice, which is different from clicking the nearest button.
Choosing Don’t ask again stops the reminders. It does not exempt your account from the change described in Is it required?. When two-factor authentication becomes mandatory, every account will need it, including the ones that asked not to be reminded.
We would rather ask more than once than have an account compromised because nobody mentioned it. You can turn two-factor authentication on at any time from Settings, whatever you chose on the prompt.