Skip to main content

Setting up MFA for your PMS access

How to set up multi-factor authentication (MFA) for your Lavanda PMS sign-in using an authenticator app, how to sign in once it is set up, and how to fix the most common enrolment problems.

Multi-factor authentication (MFA), also known as two-factor authentication or 2FA, is required for every user who signs in to the Lavanda PMS. It cannot be switched off for an account.

 

MFA adds a second check to your sign-in: your password, or the Google sign-in option, plus a one-time code, sometimes called a one-time passcode or OTP, from an authenticator app on your phone.

 

Before you begin

  • You need an active PMS user account. If you have not been invited yet, ask an Admin user in your workspace, or contact Support through Ava.

  • You need a phone with a supported authenticator app installed: Google Authenticator, Auth0 Guardian, Microsoft Authenticator, Twilio Authy or Salesforce Authenticator.

  • Sign in to the authenticator app with the same email address you use to sign in to Lavanda. Enrolling under a different account, such as a personal Gmail, is the most common cause of failure.

  • Enrol on a device you will have with you whenever you sign in, because you are asked for a code every time.

 

What you need to know

This is what appears at your next sign-in:

The Lavanda PMS sign-in page asking for a one-time code, with the Enter your one-time code field and the Continue button

After signing in with your email address and password, or with the Google sign-in option, you are asked for a one-time code from your authenticator app.

 

The first time, you are shown an enrolment page with a QR code. You scan this with your authenticator app to link it to your Lavanda account:

The Lavanda MFA enrolment page showing the QR code to scan, the Trouble Scanning link, the Enter your one-time code field and the Continue button

Lavanda supports the most commonly used authenticator apps: Google Authenticator, Microsoft Authenticator, Salesforce Authenticator, Twilio Authy and the Auth0 Guardian app.

 

Which authenticator app should you use?

Any supported app works. Choose the one your organisation already uses, then follow its set-up guide:

Most apps give you a 6 digit code that changes every 30 seconds. Salesforce Authenticator works differently: it uses a two-word phrase and asks you to approve the sign-in in the app.

 

Signing in once MFA is set up

  1. Enter your email address and password on the PMS sign-in page, or use the Google sign-in option.

  2. Open your authenticator app and find the lavanda entry.

  3. Enter the code. Most apps give a 6 digit code. Salesforce Authenticator uses a two-word phrase instead.

  4. Select Continue.

 

Troubleshooting

The QR code link has expired

If you have just been invited to the PMS, have not signed in yet, and an expired message appears when setting up MFA for the first time:

  • Ask an Admin user in your workspace, or Support through Ava, to resend your PMS invite.

 

Enrolment keeps failing

This is usually caused by more than one Lavanda entry in your authenticator app.

  • Remove all existing Lavanda entries from the app.

  • Open the Lavanda sign-in page in an incognito window, then scan the QR code to enrol again.

  • Check the app is signed in with the same email address you use to sign in to Lavanda. If it is signed in under a different address, switch to the correct one before enrolling again.

 

It worked before and now it does not

  • Check your authenticator app is signed in with the same email address you use to sign in to Lavanda, not a personal account.

  • Try an incognito window, and clear your browser cache and cookies.

  • If it still fails, contact Support through Ava. Support can reset your MFA enrolment, and you then enrol again.

  • Before enrolling again, remove any previous Lavanda entries from your app to avoid confusion during setup.

 

App-specific problems

Some problems are specific to one app. If you use Google Authenticator and a Page expired error appears after entering your code, your device clock is probably out of sync. The fix is in Set up MFA with Google Authenticator.

 

Things to note

  • MFA is required for every PMS account and cannot be deactivated.

  • Each person should have their own PMS user account. MFA is enrolled per account, on that person's device.

  • Codes change every 30 seconds, so enter the code promptly. If it is about to change, wait for the next one.

  • If you lose or replace your phone, contact Support through Ava to have your MFA enrolment reset, then enrol again on the new device.

  • Removing the Lavanda entry from your authenticator app does not turn MFA off. You are asked to enrol again at your next sign-in.

 

Getting help

Contact Support through Ava, our AI Support Agent, available 24 hours a day.

  • In the PMS, select the blue chat bubble on any page, or the Need help? link in the navigation.

  • If you cannot sign in at all, open the Lavanda Help Centre and use the chat bubble there.

Describe the problem clearly, for example "I cannot complete MFA enrolment, the QR code shows as expired". Ava will guide you through the fix and hand you to the Human Support team when it needs to.

 

Find out more

Did this answer your question?