---
title: Two Factor Authentication
slug: portal-sub/two-factor-authentication
docTags: 
createdAt: 2026-03-04T12:03:15.286Z
---

# ::embed[]{url="https://www.youtube.com/embed/jIkMgUULUiI?&wmode=opaque"}

Intrahealth has enabled two-factor authentication to allow rich client use anytime and anywhere, i.e., externally. Two-factor authentication uses the combination of something you know, which is your password, and something you have, which is your cell phone or email address. User authentication is critical because the ability to use rich client anytime and anywhere means the servers are open to the Internet.Customers can also choose to use two-factor authentication for additional internal security, i.e., within the clinic.

## Requirements

Profile build of 8.4.66.14 (SMS PIN code delivery) or 8.4.70.21 (Email PIN code delivery) and higher.

SMS or Email must be enabled in the clinic for two-factor authentication functionality.

Connectivity will be converted from TCP-IP to HTTPS (done by Intrahealth). For information on HTTPS configuration required after the conversion, please see the HTTPS Configuration topic sheet.

Complex password enforcement is required when HTTPS connections are enabled. The complex password macro will be enabled for all users and all passwords will need to be changed. The complex password requirements are a minimum of 10 characters and a maximum of 25 characters. Some special characters are allowed but not mandatory: ! @ # $ % ^ ( ) \{ } \[ ] \< > ; : ‘ “

## Configuration

Please note, configuration must be done by the Sys Admin user as an internal user, i.e., in the clinic and, in BC, on the PPN. Otherwise, there is the risk of locking yourself and all external users out of the system. Initially in NB, Intrahealth helpdesk is working in concert with a clinic user to configure two-factor authentication.

1. Go to **Organization/Preferences/Security (Global)** and select the **Security** tab.

::Image[]{src="https://api.qa.archbee.co/api/optimize/zICxj0dnLereb6UUrBA3-/BViOFsz9HecScsTm23EsN_ybeksiurjmfels0gtvulrabfwurpqs9ug.png" size="100" isUploading="false" initialPath="assets/YbekSIUrjMfELs0gtvuL_RaBFwurpQS9Ug.png" githubPath="en/General Settings and Configuration/Authentication/assets/YbekSIUrjMfELs0gtvuL_RaBFwurpQS9Ug.png" position="flex-start" showCaption="false" indent="2"}

2. In the **Two factor** dropdown field, select **SMS** or **Email** and check the **Require 2 factor authentication for external log-ins** checkbox located underneath.

::Image[]{src="https://api.qa.archbee.co/api/optimize/zICxj0dnLereb6UUrBA3-/xQDuFjaIDTIgqVAUCh35x_x1lt2orp-sx6etgwpcucpkgfziasvjq.png" size="85" isUploading="false" initialPath="assets/X1lt2orP-SX_6_eTgwpcu_cPkgfziASVJQ.png" githubPath="en/General Settings and Configuration/Authentication/assets/X1lt2orP-SX_6_eTgwpcu_cPkgfziASVJQ.png" position="flex-start" showCaption="false" indent="2"}

:::Paragraph{indent="1"}
The Two factor survival period, the period during which the authentication of the user and their machine is remembered, is set to 28 days by default. If the clinic would like to change the number of days, our recommendation is to reduce the number of days.The PIN Survival preference is set to 5 mins before the PIN times out. The clinic can customize this setting to allow time for the email with the PIN to be delivered, as email delivery can take longer than SMS delivery.Press OK to save the changes and close the window.
:::

:::hint{type="danger"}
**Note**

As a complex password for all users is now required for Profile, there is an extra password setting in the **Unlock** panel of the Global Security Preferences window. Check the **Allow truncation to \[ ] chrs** checkbox to set the shortening of the password on the Profile lock screen to a chosen number of characters, with the default being 3 characters. This ensures that workflow for everyone isn’t interrupted by having to type in the full complex password throughout the workday.
:::

3. Go to **Organization/People & Places**, open the desired provider/user’s profile and select the **General** view.

::Image[]{src="https://api.qa.archbee.co/api/optimize/zICxj0dnLereb6UUrBA3-/kCAElKkadU2KJkd-JWl8U_moayx3r5nsorsczkfy6em3tygox4gtjca.png" size="100" isUploading="false" initialPath="assets/MoAy_X3R5NSORsczKFY6em3TYgox4gtJCA.png" githubPath="en/General Settings and Configuration/Authentication/assets/MoAy_X3R5NSORsczKFY6em3TYgox4gtJCA.png" position="flex-start" showCaption="false" indent="2"}

4. Enter the provider/user’s cell phone number in the **Cell Phone** field or their email address in the **E-Mail** field. This number or email address is used to receive the PIN code as part of the two-factor authentication. Press **Apply** to save the information and leave the window open.
5. Select the **Special** view in the desired provider/user’s profile.

::Image[]{src="https://api.qa.archbee.co/api/optimize/zICxj0dnLereb6UUrBA3-/AGkTIawacsjP9LgTnOmpJ_s9momh1oqmuigoakvnuerqrpicrq-pvyg.png" size="100" isUploading="false" initialPath="assets/S9MOmh1oqmuigOA_KvnUErQRpicRq-pvYg.png" githubPath="en/General Settings and Configuration/Authentication/assets/S9MOmh1oqmuigOA_KvnUErQRpicRq-pvYg.png" position="flex-start" showCaption="false" indent="2"}

6. Check the **User can log in externally** checkbox.If the two-factor method selected was **SMS**, the provider/user’s cell phone number will display in a **SMS number** field with a green checkmark. If the two-factor method selected was **Email**, the provider/user’s email address will display in an **E-Mail** field with a green checkmark. If the required information is missing, a warning triangle will display in the **SMS number** or **E-Mail** field:

::Image[]{src="https://api.qa.archbee.co/api/optimize/zICxj0dnLereb6UUrBA3-/-YLwgok6IMNnE_2P4WZbf_0ftqfpqpwlivlafzdcysz4cqik8hoycw.png" size="35" isUploading="false" initialPath="assets/0FTqFpQPwli_VlAFZdCySz4cqIK8Hoy_Cw.png" githubPath="en/General Settings and Configuration/Authentication/assets/0FTqFpQPwli_VlAFZdCySz4cqIK8Hoy_Cw.png" position="flex-start" showCaption="false" indent="2"}

:::hint{type="danger"}
**Note**

To enable two-factor authentication for users logging in ***within*** the clinic, you will need to check the **Use two factors on log in** checkbox.
:::

Press OK to save the changes and close the window\.7. Log out and log back in to configure the next provider or user.

## Workflow

1. When you (or any user or provider) log in, an Enter PIN window opens, with an **Enter PIN** field.

::Image[]{src="https://api.qa.archbee.co/api/optimize/zICxj0dnLereb6UUrBA3-/nidi4DX48EbCbUBq-qdeO_akmj7reqs-xlarm5ncqnj9f21-tobglgdq.png" size="79" isUploading="false" initialPath="assets/AKMJ7reQS-xLARM5nCQNJ9f21-toBGlgDQ.png" githubPath="en/General Settings and Configuration/Authentication/assets/AKMJ7reQS-xLARM5nCQNJ9f21-toBGlgDQ.png" position="flex-start" showCaption="false" indent="2"}

:::Paragraph{indent="1"}
You can check the **Trust this computer** checkbox, so Profile remembers the authentication of you and your machine for the number of days set in the **Two factor survival period** field in the **Security** tab of the Global Security Preferences window. If a different user logs into Profile on the same computer, they will be asked for their PIN to validate them as a trusted person, even though they are already using a trusted computer.If you log into another computer and check the **Trust this computer** checkbox on that computer, your previous computer will no longer be trusted and will require you to enter a PIN the next time you log in.If the **Trust this computer** checkbox isn’t checked, the Enter PIN window will appear for you at every login.
:::

:::hint{type="danger"}
**Note**

It is important that public computers are ***not*** trusted.
:::

2. Once you receive your PIN by SMS on your cell phone (see screenshot below) or by email, enter the PIN in the **Enter PIN** field, press **OK&#xA0;**&#x61;nd you will be logged in. If another PIN needs to be sent, press **Send another PIN**. A 30-second countdown will be displayed.

:::hint{type="danger"}
**Note**

The PIN code sent to you will expire after 3 minutes. When this happens, a PIN code expiry dialog box appears in Profile. It states the PIN code sent to you has expired and offers to send another PIN. Press **OK** to receive another PIN or **Cancel** to close the PIN code expiry dialog box and go back to the login window. A hint text shows that the two-factor authentication was cancelled.
:::

::Image[]{src="https://api.qa.archbee.co/api/optimize/zICxj0dnLereb6UUrBA3-/KR8BS8mmX9w7HeR6uQnBS_e8llsmvscuemsmyvpcs92myz7f-mlaowha.png" size="43" isUploading="false" initialPath="assets/e8lLSMVsCueMSMYvPCs92mYz7f-mLaOWHA.png" githubPath="en/General Settings and Configuration/Authentication/assets/e8lLSMVsCueMSMYvPCs92mYz7f-mLaOWHA.png" position="flex-start" showCaption="false"}



