---
title: Two-Factor Authentication (New Brunswick)
slug: portal-sub/two-factor-authentication-new-brunswick
docTags: 
createdAt: 2026-03-04T12:03:15.297Z
---

# ::embed[]{url="https://www.youtube.com/embed/jIkMgUULUiI?&wmode=opaque"}

# Two-Factor Authentication (New Brunswick)

Intrahealth has enabled two-factor authentication to allow rich client use anytime and anywhere, i.e., externally.  Two-factor authentication uses the combination of something you know, which is your password, and something you have, which is your cell phone or email address.  User authentication is critical because the ability to use rich client anytime and anywhere means the servers are open to the Internet.

Customers can also choose to use two-factor authentication for additional internal security, i.e., within the clinic.

## Requirements

Profile build of 8.4.66.14 (SMS PIN code delivery) or 8.4.70.21 (Email PIN code delivery) and higher.

SMS or Email must be enabled in the clinic for two-factor authentication functionality.

Complex password enforcement is required when HTTPS connections are enabled.  The complex password requirements are a minimum of 10 characters and a maximum of 25 characters.  Some special characters are allowed but not mandatory: ! @ # $ % ^ ( ) \{ } \[ ] \< > ; : ‘ “

## Configuration

Please note, configuration ***must*** be done by the Sys Admin user as an internal user, i.e., in the clinic.  Otherwise, there is the risk of locking yourself and all external users out of the system.  Initially in NB, Intrahealth helpdesk is working in concert with a clinic user to configure two-factor authentication.

1. Go to Organization/Preferences/Security (Global)and select the Security tab.

::Image[]{src="https://api.qa.archbee.co/api/optimize/zICxj0dnLereb6UUrBA3-/-KLJ37TzaaDPX-cSkdC-7_tmqvm0sq2ihr8k3do7z4wxqia0kzwh7bia.png" size="94" isUploading="false" initialPath="assets/tMQVM0sQ2iHR8K3DO7Z4wXQIa0KzwH7bIA.png" githubPath="en/General Settings and Configuration/Authentication/assets/tMQVM0sQ2iHR8K3DO7Z4wXQIa0KzwH7bIA.png" position="flex-start" showCaption="false" indent="2"}

3. In the Two factor dropdown field, select SMS or Email and check the Require 2 factor authentication for external log-ins checkbox located underneath.

::Image[]{src="https://api.qa.archbee.co/api/optimize/zICxj0dnLereb6UUrBA3-/zNYWW63_j5_IjVhtMxhHz_cyi5llkxoukk1ohr8svezsjg4jlghtaphg.png" size="55" isUploading="false" initialPath="assets/CYI5LlKxOUKK1OHR8SvEzSJG4jlGhTapHg.png" githubPath="en/General Settings and Configuration/Authentication/assets/CYI5LlKxOUKK1OHR8SvEzSJG4jlGhTapHg.png" position="flex-start" showCaption="false"}

The Two factor survival period, the period during which the authentication of the user and their machine is remembered, is set to 28 days by default.   If the clinic would like to change the number of days, our recommendation is to *reduce* the number of days.

The PIN Survival preference is set to 5 mins before the PIN times out.  The clinic can customize this setting to allow time for the email with the PIN to be delivered, as email delivery can take longer than SMS delivery.

Press

::Image[]{src="https://api.qa.archbee.co/api/optimize/zICxj0dnLereb6UUrBA3-/WLzJ7OCncXUNKUW8lunWu_nlkqnoto1x1efdna7n1dbggiqwsktdsmiq.png" size="11" isUploading="false" initialPath="assets/NLKqnotO1x1EfdNA7n1dBgGIqWSKtDSMiQ.png" githubPath="en/General Settings and Configuration/Authentication/assets/NLKqnotO1x1EfdNA7n1dBgGIqWSKtDSMiQ.png" position="flex-start" showCaption="false"}

 to save the changes and close the window.

| NOTE:                                                                                                                                                                                                                                                                                                                                                                                                                          |   |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | - |
| There is an extra password setting in the Unlock panel of the Global Security Preferences window.  Check the Allow truncation to \[  ] chrs checkbox to set the shortening of the password on the Profile lock screen to a chosen number of characters, with the default being 3 characters.  This ensures that workflow for everyone isn’t interrupted by having to type in the full complex password throughout the workday. |   |

1. Go to Organization/People & Places, open the desired provider/user’s profile and select the General view.

::Image[]{src="https://api.qa.archbee.co/api/optimize/zICxj0dnLereb6UUrBA3-/M5DxASvNzX89FlSDR68CB_spouzliov7k6l4knmkhjee5hww1m5ekqa.png" size="100" isUploading="false" initialPath="assets/spouzliOV7K6l_4KNmkhJEe5Hww1m5eKqA.png" githubPath="en/General Settings and Configuration/Authentication/assets/spouzliOV7K6l_4KNmkhJEe5Hww1m5eKqA.png" position="flex-start" showCaption="false" indent="2"}

2. Enter the provider/user’s cell phone number in the Cell Phone field or their email address in the E-Mail field.  This number or email address is used to receive the PIN code as part of the two-factor authentication.  Press

::Image[]{src="https://api.qa.archbee.co/api/optimize/zICxj0dnLereb6UUrBA3-/ClfhoxWZYFZKixJQeZ2ZA_gv6mml8kie1mewymzymcnwg0imff1ekt5g.png" size="11" isUploading="false" initialPath="assets/gv6mmL8Kie1MewyMZYMcNwg0iMFf1ekt5g.png" githubPath="en/General Settings and Configuration/Authentication/assets/gv6mmL8Kie1MewyMZYMcNwg0iMFf1ekt5g.png" position="flex-start" showCaption="false" indent="2"}

:::Paragraph{indent="1"}
 to save the information and leave the window open.
:::

3. Select the Special view in the desired provider/user’s profile.

::Image[]{src="https://api.qa.archbee.co/api/optimize/zICxj0dnLereb6UUrBA3-/tEVq9V0omO_LiZEQLRM5y_izouvc0hmgxvj-fwdj0hkyv5g2kuvebua.png" size="100" isUploading="false" initialPath="assets/Izouvc0hmgXVj-FwDj0hKYV5G2K_UVEbUA.png" githubPath="en/General Settings and Configuration/Authentication/assets/Izouvc0hmgXVj-FwDj0hKYV5G2K_UVEbUA.png" position="flex-start" showCaption="false" indent="2"}

4. Check the User can log in externally checkbox.

If the two-factor method selected was SMS, the provider/user’s cell phone number will display in a SMS number field with a green checkmark.  If the two-factor method selected was Email, the provider/user’s email address will display in an E-Mail field with a green checkmark.   If the required information is missing, a warning triangle will display in the SMS number or E-Mail field:

::Image[]{src="https://api.qa.archbee.co/api/optimize/zICxj0dnLereb6UUrBA3-/2Ujsif8LDV1Ufr6se1Qag_cfhhydzhkw7dafnzvri-tnwltusbprlvwq.png" size="32" isUploading="false" initialPath="assets/CFHHYDzHkw7dAfnzVri-TnwLtUSBPRLVWQ.png" githubPath="en/General Settings and Configuration/Authentication/assets/CFHHYDzHkw7dAfnzVri-TnwLtUSBPRLVWQ.png" position="flex-start" showCaption="false"}

.

| NOTE:                                                                                                                                            |   |
| ------------------------------------------------------------------------------------------------------------------------------------------------ | - |
| To enable two-factor authentication for users logging in ***within*** the clinic, you will need to check the Use two factors on log in checkbox. |   |

Press

::Image[]{src="https://api.qa.archbee.co/api/optimize/zICxj0dnLereb6UUrBA3-/TUTwVcHl5ScVTFrvl0pV1_hwrgzgmjypdegkloaz4nxyd9kfqfpnodyw.png" size="11" isUploading="false" initialPath="assets/hwRgZgMjyPDEgKLoaz4NXYD9kFQfPnoDYw.png" githubPath="en/General Settings and Configuration/Authentication/assets/hwRgZgMjyPDEgKLoaz4NXYD9kFQfPnoDYw.png" position="flex-start" showCaption="false"}

 to save the changes and close the window.

1. Log out and log back in to configure the next provider or user.

## Workflow

1. When you (or any user or provider) log in, an Enter PIN window opens, with an Enter PIN field.

::Image[]{src="https://api.qa.archbee.co/api/optimize/zICxj0dnLereb6UUrBA3-/A-DLXEZaWBVwf42IC6R1c_ov-qexfvlzrad5z8asc6p3ihyyigmo5alq.png" size="50" isUploading="false" initialPath="assets/ov-QeXfVLzRAd5Z8ASc6p3ihyYIGmo5aLQ.png" githubPath="en/General Settings and Configuration/Authentication/assets/ov-QeXfVLzRAd5Z8ASc6p3ihyYIGmo5aLQ.png" position="flex-start" showCaption="false"}

You can check the Trust this computer checkbox, so Profile remembers the authentication of you and your machine for the number of days set in the Two factor survival period field in the Security tab of the Global Security Preferences window.   If a different user logs into Profile on the same computer, they will be asked for their PIN to validate them as a trusted person, even though they are already using a trusted computer.

If this checkbox isn’t checked, the Enter PIN window will appear for you at every login.

| NOTE:                                                        |   |
| ------------------------------------------------------------ | - |
| It is important that public computers are ***not*** trusted. |   |

1. Once you receive your PIN by SMS on your cell phone (see screenshot below) or by email, enter the PIN in the Enter PIN field, press

::Image[]{src="https://api.qa.archbee.co/api/optimize/zICxj0dnLereb6UUrBA3-/dMiSzi-maw8Xy-jCSyBX4_fusnkq24fmrpu0fx5wjy2e6z63sictxdag.png" size="11" isUploading="false" initialPath="assets/fusnKq24FmrPu0FX5Wjy2E6z63sIcTXDag.png" githubPath="en/General Settings and Configuration/Authentication/assets/fusnKq24FmrPu0FX5Wjy2E6z63sIcTXDag.png" position="flex-start" showCaption="false" indent="2"}

:::Paragraph{indent="1"}
and you will be logged in. If another PIN needs to be sent, press
:::

::Image[]{src="https://api.qa.archbee.co/api/optimize/zICxj0dnLereb6UUrBA3-/oka4C2HHse_hOE0eUCxUD_nuho2vefsoghtabhg5gmfve9qbdrfb09ta.png" size="17" isUploading="false" initialPath="assets/nUHo2veFSoghtaBHg5GMfvE9QBdrfB09tA.png" githubPath="en/General Settings and Configuration/Authentication/assets/nUHo2veFSoghtaBHg5GMfvE9QBdrfB09tA.png" position="flex-start" showCaption="false" indent="2"}

:::Paragraph{indent="1"}
. A 30-second countdown will be displayed.
:::

| NOTE:                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |   |
| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | - |
| ::Image[]{src="https://api.qa.archbee.co/api/optimize/zICxj0dnLereb6UUrBA3-/d5X8yboJODtO0K-246Liy_bnorp1csa94xn6exwn9tgtcmqxhvnlw2yq.png" size="11" isUploading="false" initialPath="assets/bNorp1Csa94XN6eXWn9TGTcMQXHVNlw2YQ.png" githubPath="en/General Settings and Configuration/Authentication/assets/bNorp1Csa94XN6eXWn9TGTcMQXHVNlw2YQ.png" position="flex-start" showCaption="false"}::Image[]{src="https://api.qa.archbee.co/api/optimize/zICxj0dnLereb6UUrBA3-/uOIqRveV5WAMEaT7yIbCF_ypvibzicqlwstcc8mfnn8h1vfvtfhe1eew.png" size="11" isUploading="false" initialPath="assets/ypvibZicqLwstcc8mFnn8h1vfvtfhE1Eew.png" githubPath="en/General Settings and Configuration/Authentication/assets/ypvibZicqLwstcc8mFnn8h1vfvtfhE1Eew.png" position="flex-start" showCaption="false"}<br />The PIN code sent to you will expire after 3 minutes.  When this happens, a PIN code expiry dialog box appears in Profile. It states the PIN code sent to you has expired and offers to send another PIN.  Press<br />to receive another PIN or<br /> to close the PIN code expiry dialog box and go back to the login window.  A hint text shows that the two-factor authentication was cancelled. |   |

::Image[]{src="https://api.qa.archbee.co/api/optimize/zICxj0dnLereb6UUrBA3-/6rl7u2d5qer0Nc_fD3CV3_rcbf9czdqxi-tyvpyduxwvny1neeetzxnw.png" size="64" isUploading="false" initialPath="assets/Rcbf9CzDqxi-tYvPyduxWVNy1neEEtzxnw.png" githubPath="en/General Settings and Configuration/Authentication/assets/Rcbf9CzDqxi-tYvPyduxWVNy1neEEtzxnw.png" position="flex-start" showCaption="false"}
