Release Notes July 2026 - Multi-Factor Authentication (MFA)

Account security is one of the most important parts of every HR platform. Yomly already protects access through each organisation's configured login method, and this release adds another layer of protection for employees who sign in with their Yomly email and password.

We are introducing Multi-Factor Authentication (MFA) for Yomly credentials-based logins on web and the Yomly mobile app. MFA helps protect user accounts by asking for a second verification step after the password is entered. This second step uses a time-based 6-digit code from an authenticator app, such as Google Authenticator or Microsoft Authenticator.

Employees may use MFA in different ways depending on their organisation's policy and device. The sections below separate the required setup flow, the optional self-service setup flow, the sign-in step employees will see after MFA is active, and the mobile app setup experience.

Before starting setup, employees should install a compatible authenticator app on their device, such as Google Authenticator or Microsoft Authenticator. These apps are available from the Google Play Store for Android devices and the Apple App Store for iPhone devices.

If your organisation wants MFA to be required for employees, please contact the Yomly Support team. The Yomly team will help make MFA required for the organisation and confirm when employees should begin the setup flow.

How to set up MFA when it is required by your organisation

When MFA is required for an organisation, employees who have not yet set it up will be guided through enrolments the next time they log in. The process is simple: sign in with Yomly credentials, scan the QR code shown on screen using an authenticator app, enter the 6-digit code, and continue to the dashboard once setup is complete.

If the QR code cannot be scanned, the employee can use the Can't scan? option to view the setup key and enter it manually in their authenticator app. This creates the same Yomly MFA entry as scanning the QR code.

Screenshot note: These screens show the first-time MFA enrolment flow that appears when MFA is required for the organisation.

 


Screenshot note: The Can't scan? screen provides a setup key for employees who cannot scan the QR code with their authenticator app.

 

Once the authenticator app shows a Yomly code, the employee enters the current 6-digit code in Yomly to complete setup.
 

After setup is complete, Yomly confirms that MFA is enabled and the employee can continue into Yomly.

 

How to set up MFA yourself when it is optional

If MFA is not mandatory for an organisation, existing users can still choose to enable it themselves from their employee profile. This is useful for employees who want the additional account protection even when it is not required by company policy.

Existing users can go to Employee Profile > Security, select Set Up MFA, scan the QR code using an authenticator app, enter the 6-digit code, and verify setup. Once verified, MFA becomes active for future sign-ins.


If the QR code cannot be scanned, the employee can use the Can't scan? option to view the setup key and enter it manually in their authenticator app. This creates the same Yomly MFA entry as scanning the QR code.

 


Screenshot note: These screens show where an existing user opens the Security tab, selects Set Up MFA, and completes setup from their own profile when MFA is optional.

If an employee has enabled MFA themselves and their organisation's policy allows it, they can disable MFA from their employee profile. If MFA is required by the organisation, employees cannot disable it themselves; only an HR Admin can disable MFA for that employee.

How to sign in after MFA is set up

After MFA has been set up, future sign-ins include an additional verification step. Employees enter their email and password as usual, then enter the current 6-digit code from their authenticator app before accessing Yomly.

 

Using MFA in the Yomly mobile app

Yomly uses an authenticator app to generate a new 6-digit code every 30 seconds. During setup, the user connects Yomly to an authenticator app using the QR code, the setup key, or the Open authenticator app action. After setup, the user enters the current code whenever Yomly asks for two-step verification.

Enrollment Page

The enrollment page is shown as "Setup 2FA". The user should keep this page open until the authenticator app has a Yomly entry and is showing a 6-digit code.

Option 1: Scan the QR code

This is the simplest option when the user has the authenticator app on another device or can scan from the current device.

  1. Open Google Authenticator, Microsoft Authenticator, or another compatible authenticator app. 

  2. Choose the option to add a new account.
  3. Choose Scan QR code.
  4. Scan the QR code shown on the Yomly setup screen.
  5. Confirm that a Yomly account appears in the authenticator app and starts generating 6-digit codes.

    QR code setup

    .       .    
    Screenshot showing the QR code area and the authenticator app scan option.

 

Option 2: Copy and enter the setup key

Use this option when the QR code cannot be scanned. The setup key creates the same authenticator entry as the QR code.

  1. Tap "Can't scan? Enter key manually" on the Yomly setup screen.
  2. Find the "Setup key" and tap the copy icon if the user wants to copy it.
  3. In the authenticator app, choose ‘Enter a setup key’ or a similar option.
  4. Enter an account name such as ‘Yomly’ or ‘Yomly: <username>’, then paste or type the setup key.
  5. If the authenticator app asks for a key type, choose time-based.
  6. Save the account and wait for the 6-digit code to appear.
  7. Copy the 6-digit code and paste it into the six boxes at the end of Yomly setup screen.

Manual setup key
.            


 

Option 3: Open Authenticator App

The "Open authenticator app" button helps the user move from Yomly into an authenticator app when the device supports it.

  • On Android, tapping the button opens a compatible authenticator app using the Yomly setup link. The authenticator app can then add the Yomly account automatically or ask the user to confirm the account details.
  • If Android cannot find an authenticator app, Yomly shows a bottom sheet explaining that the user should install an app such as Google Authenticator or Microsoft Authenticator, then try again.
  • On iOS, Yomly shows a guidance bottom sheet instead of automatically setting up the authenticator app. The user should open the authenticator app, add an account manually, and use the setup key or QR code from the Yomly setup page as explained above.

 

Finish Enrollment

After the Yomly account has been added to the authenticator app, the user returns to Yomly and verifies the setup.

  1. Tap the Yomly entry in the authenticator app to copy the 6-digit code.
  2. Enter the current 6-digit code into the Yomly verification field.
  3. Tap "Verify & enable". The button is available after all six digits are entered.
  4. If the code is rejected, check the authenticator app and try the newest code.
  5. When setup is complete, Yomly shows "You're all set!" and the user can continue to Yomly.

Enrollment success

    

 

Verification During Sign-In

After MFA has been enabled, Yomly may show "Two Step Verification" during sign-in. The user does not need to scan a QR code again; they only need the current code from their authenticator app.

  1. Open the authenticator app.
  2. Find the Yomly account entry and tap on it to copy the 6-digit code.
  3. Paste or enter the current 6-digit code into Yomly.
  4. Tap "Verify & continue". The app may also submit automatically after all six digits are entered.
  5. On success, Yomly completes sign-in and opens the app.

Two Step Verification page


 

Screenshot showing the code input field, Verify & continue button, and the code refresh hint.

 

If Something Goes Wrong

  • Invalid code: check that the code is for Yomly, wait for the next 30-second code if needed, then try again.
  • Code changed while typing: use the newest code shown in the authenticator app.
  • Session expired: sign in again and restart verification.
  • Access denied: contact the HR Administrator to receive access.
  • No authenticator app found: install Google Authenticator, Microsoft Authenticator, or another compatible app, then retry setup or use the setup key.

 

Mobile setup summary

The QR code, setup key, and Open authenticator app action are three ways to create the same Yomly entry in an authenticator app. The user only needs one setup method. Once the authenticator app shows a Yomly code, the user returns to Yomly, enters the current 6-digit code, and completes setup. For future sign-ins, the user simply enters the latest Yomly code from the authenticator app.

For organisations using Single Sign-On (SSO), employees will continue to authenticate through their existing identity provider. Yomly MFA does not change the login experience for SSO users, because any additional authentication requirements are handled by the organisation's identity provider.

If an employee loses access to their authenticator app or cannot complete verification, they should contact their HR Admin or support team for assistance. Once access is reset, the employee may be asked to enrol again the next time they log in, depending on the organisation's MFA policy.

This release is focused on strengthening account protection while keeping the login experience clear and familiar. For most users, the only visible change is the addition of a quick verification code during login after MFA has been set up.

Was this article helpful?
0 out of 0 found this helpful

Comments

0 comments

Article is closed for comments.