For the complete documentation index, see llms.txt. This page is also available as Markdown.

Account Security

Protect your PEARS account with two-factor authentication (2FA) and passkeys from the Security tab in Account Settings.

Non-SSO users can add extra protection to their PEARS account from the Security tab in Account Settings. From here you can enable two-factor authentication (2FA) with an authenticator app, generate recovery codes, and register passkeys for passwordless sign-in.

TIP: The Security tab is not shown for users whose email domain signs in through single sign-on (SSO/SAML). Those accounts are protected by your identity provider, so PEARS-managed 2FA and passkeys do not apply.

Open the Security Tab

Open Account Settings from the user menu in the top navigation bar, then click the Security tab.

Two-Factor Authentication (Authenticator App)

Two-factor authentication requires a one-time code from an authenticator app (such as Google Authenticator, Microsoft Authenticator, or 1Password) in addition to your password when you sign in.

1

Start setup

On the Security tab, find Authenticator App and click to begin setup.

2

Scan the QR code

Scan the displayed QR code with your authenticator app. If you can't scan it, use the Use the setup key option to reveal a key you can enter manually.

3

Confirm the code

Enter the one-time code shown in your authenticator app to confirm setup and activate two-factor authentication.

After 2FA is enabled, you'll be prompted for a one-time code each time you sign in with your password.

Recovery Codes

When you enable two-factor authentication, PEARS provides a set of one-time recovery codes. Store these somewhere safe — if you lose access to your authenticator app, a recovery code lets you sign in. You can regenerate a new set from the Security tab at any time, which invalidates the previous codes.

Passkeys

A passkey lets you sign in without a password using your device's built-in security (such as Touch ID, Windows Hello, or a hardware security key).

1

Add a passkey

On the Security tab, click to add a passkey and follow your browser or device prompts to create it.

2

Sign in with a passkey

On the sign-in page, click Sign in with a passkey, or select your saved passkey from your browser or password manager's autofill prompt. A passkey is also available on the event registration sign-in page.

The Security tab lists each registered passkey with the date it was added, and you can remove a passkey you no longer use.

Require Two-Factor Authentication for Your Organization

Organization administrators can require all members to use two-factor authentication. See Organization Settings for the Authentication panel.

When enforcement is on, any non-SSO member without a 2FA factor is sent to the setup pages at sign-in and cannot use the rest of PEARS until they enroll. SSO users and staff are exempt, and enrolling once covers all organizations the user belongs to.

Reset a User's MFA and Passkeys

If a member is locked out — for example, they lost their device or authenticator — an organization administrator can reset their factors so they can start over.

  1. Open Organization Settings → People & Access → Users and open the locked-out user.

  2. Click Reset MFA & Passkeys.

This removes the user's authenticator, passkeys, and recovery codes, so they re-enroll from scratch the next time they sign in. The affected user is notified by email and in their PEARS inbox. This option is available only to organization administrators and is hidden for SSO-managed accounts.

Last updated