linelo Help centre
CurrentChecked against the product 22 September 2026

Two-factor authentication for office logins

For the office Updated 22 September 2026 3 sections · 2 min read

Two-factor means a stolen password isn’t enough to get in: signing in asks for a 6-digit code as well. Two ways to get it — an authenticator app on your phone (Google Authenticator, Microsoft Authenticator, Authy, or the one in your password manager), or a code emailed to you each time you sign in. Email is the simpler one; the app is the stronger one.

Codes by email

  1. Open Account (bottom of the sidebar) and hit Email me a code.
  2. A code lands in your inbox. Enter it and hit Turn on — that proves the inbox works before anything changes.
  3. From then on, signing in is email, password, then the code from the email. Each code lasts 10 minutes and works once; Send a new code on the sign-in page gets you another.

Or an authenticator app

  1. In the portal, open Account (bottom of the sidebar) and hit Use an authenticator app.
  2. In your authenticator app, tap add and scan the QR code on screen. Can’t scan? Type the code shown next to it instead.
  3. Enter the 6-digit code the app now shows and hit Turn on two-factor again to confirm.
  4. Save the recovery codes it gives you — in a password manager, or printed and put away. Each one gets you in once if you ever lose your phone. They’re only shown this once.

From then on, signing in is email, password, then the code. Lost your phone? Sign in with one of your recovery codes, then set up the new phone from Account — or switch to codes by email. Out of codes too? An owner can clear your two-factor from Admins with Reset 2FA.

Require it for everyone

Owners can make two-factor a rule: in Admins, hit Require it on the Require two-factor for every office login card. Anyone without it is walked through setup the next time they open the portal, before anything else, and nobody can switch theirs off while the rule is on. The Admins list shows who has it (2FA on).

Tip
Turn yours on first, then require it — so you’re never the one locked out of the switch.
Careful
The master password (signing in with the email blank) is a server setting and isn’t covered by this rule. Give everyone their own login and keep the master password for emergencies.
Was this useful? Yes No