Account Security
Protect your PEARS account with two-factor authentication (2FA) and passkeys from the Security tab in Account Settings.
Non-SSO users can add extra protection to their PEARS account from the Security tab in Account Settings. From here you can enable two-factor authentication (2FA) with an authenticator app, generate recovery codes, and register passkeys for passwordless sign-in.
TIP: The Security tab is not shown for users whose email domain signs in through single sign-on (SSO/SAML). Those accounts are protected by your identity provider, so PEARS-managed 2FA and passkeys do not apply.
Open the Security Tab
Open Account Settings from the user menu in the top navigation bar, then click the Security tab.
NOTE: Sensitive changes on the Security tab (such as adding or removing a factor) prompt you to re-enter your password before the change is saved.
Two-Factor Authentication (Authenticator App)
Two-factor authentication requires a one-time code from an authenticator app (such as Google Authenticator, Microsoft Authenticator, or 1Password) in addition to your password when you sign in.
After 2FA is enabled, you'll be prompted for a one-time code each time you sign in with your password.
Recovery Codes
When you enable two-factor authentication, PEARS provides a set of one-time recovery codes. Store these somewhere safe — if you lose access to your authenticator app, a recovery code lets you sign in. You can regenerate a new set from the Security tab at any time, which invalidates the previous codes.
Passkeys
A passkey lets you sign in without a password using your device's built-in security (such as Touch ID, Windows Hello, or a hardware security key).
The Security tab lists each registered passkey with the date it was added, and you can remove a passkey you no longer use.
Require Two-Factor Authentication for Your Organization
Organization administrators can require all members to use two-factor authentication. See Organization Settings for the Authentication panel.
When enforcement is on, any non-SSO member without a 2FA factor is sent to the setup pages at sign-in and cannot use the rest of PEARS until they enroll. SSO users and staff are exempt, and enrolling once covers all organizations the user belongs to.
Reset a User's MFA and Passkeys
If a member is locked out — for example, they lost their device or authenticator — an organization administrator can reset their factors so they can start over.
Open Organization Settings → People & Access → Users and open the locked-out user.
Click Reset MFA & Passkeys.
This removes the user's authenticator, passkeys, and recovery codes, so they re-enroll from scratch the next time they sign in. The affected user is notified by email and in their PEARS inbox. This option is available only to organization administrators and is hidden for SSO-managed accounts.
Last updated
