Enabling Multi-Factor Authentication:
Multi-Factor Authentication (MFA) adds an extra layer of security when accessing the WholesaleBackup Web Console. This setting (which is off by default) can be enabled by navigating to the user dropdown menu in the upper right hand corner of the header and selecting the Multi-Factor Authentication link. You will be taken to your Multi-factor authentication profile, where you will be prompted to go through a setup wizard.
Choosing an Authentication Method:
The Multi-Factor Authentication setup wizard will prompt you to choose your method of authentication: Token Generator, Email, or Security key or passkey.
Token Generator:
Selecting Token generator and proceeding to the next step of the setup wizard will present you with a QR code which you can scan using your preferred Authentication App (such as Google Authenticator, or Microsoft Authenticator.) Once scanned, the application will continuously generate a new token for your Web Console account in intervals of 30 seconds. To complete the wizard form, input the authenticator code you see on your mobile device into the form and click Next.
Email:
Selecting Email and proceeding to the next step of the setup wizard will send an automated email to the address that is tied to your Web Console account and will include a 6 digit code. You will need this for the next step of the form where you will confirm this method by entering the code you received and clicking Next.
Security key or passkey:
Selecting Security key or passkey and proceeding to the next step of the setup wizard will hand off to your browser, which will ask you to confirm on the device you want to use. There is no code to type at this step.
Before you confirm, your browser may ask where to save it. That choice decides which computers you will be able to sign in from afterwards:
- A security key, such as a YubiKey — works on any computer you plug it into.
- Your browser profile — works on any computer where you are signed in to the same browser.
- iCloud Keychain — works across your Apple devices.
- Touch ID or Windows Hello — works on that one computer only.
- A phone or tablet — works by scanning a QR code, but the computer you are signing in from must have Bluetooth switched on.
If you use the Web Console from more than one computer, choose a security key or your browser profile (or the Token Generator or Email from the steps above.) The other options tie your sign-in to a single machine, to one brand of device, or to a phone that has to be within Bluetooth range.
Once you confirm on the device, it is linked to your Web Console account and the setup wizard is complete.
Your browser raises this prompt on its own as soon as the step loads. If you do not see it, your browser may have blocked it — reload the page to try again.
If you do not receive an emailed token at this step, please check your email's spam folder or any filtering that may be blocking emails from support@wholesalebackup.com. You can trigger another email by clicking the 'resend email token' link at the bottom of the wizard form.
After finishing this confirmation step, multi-factor auth will be enabled.
Logging into the Web Console:
Now that Multi-Factor Authentication is enabled, you will have one more step in the login process to access the Web Console. You will enter your email and password as you have previously, and will then be prompted to confirm the second factor you set up.
If you chose Token Generator or Email, enter the code from your authenticator app or from the email we send you. If you chose Security key or passkey, your browser will prompt you to confirm on your device — tap your security key, or use Touch ID or Windows Hello — and there is no code to enter. If your security key has a PIN set on it, your browser will ask for that first. Once confirmed, you will be logged into the Web Console.
Multi-Factor Authentication Profile:
With Multi-Factor Authentication enabled, you now have access to your MFA profile. You can access the profile by clicking the link in the user dropdown menu (the same link as where you completed the setup.) Simply put, this is where you can check which method you chose (Email, Token generator, or Security key or passkey), generate backup tokens, and disable Multi-Factor Authentication. To do this, follow the link at the bottom of the form and confirm that you will be disabling MFA.
Note: To disable Multi-Factor Authentication, you must be logged into the Web Console. If you are having issues accessing your account, please contact our support team.
Backup Tokens:
Backup tokens are single-use codes that let you sign in when your usual method is not available — if you lose your security key, cannot reach your email, or are on a computer that cannot use your passkey.
From your Multi-Factor Authentication profile, select Manage Backup Tokens to generate a set. Print them or store them somewhere safe and separate from the device you normally sign in with. Each token works once, and generating a new set replaces the old one.
When you are asked for your token at sign-in, select Use Backup Token and enter one of your codes.
We recommend generating a set as soon as you enable Multi-Factor Authentication, and especially if you sign in with a security key. Note that disabling Multi-Factor Authentication clears your backup tokens along with your registered method — if you disable and re-enable, generate a new set.
Note: your account uses one authentication method at a time. To switch methods — moving from Email to a security key, for example — disable Multi-Factor Authentication on this page and then run the setup wizard again to choose the new one.
Note: signing in with a security key, passkey, or built-in authenticator needs a current web browser. On older systems that cannot run one — Windows Server 2012, for example — a plug-in security key is the only one of these options that will work. Token Generator and Email work on any browser.