Skip to main content

Account Security

This guide covers password management, multi-factor authentication (MFA), and session security in Taskr.

Accessing Security Settings

Navigate to Account > Security or go to /account/security.

Password Management

Password Requirements

Strong passwords must include:

Changing Your Password

  1. Go to Account > Security
  2. Click Change Password
  3. Enter current password
  4. Enter new password
  5. Confirm new password
  6. Click Update Password

Forgot Password

If you can’t log in:
  1. Click Forgot Password on login page
  2. Enter your email
  3. Check email for reset link
  4. Click link and create new password

Multi-Factor Authentication (MFA)

What is MFA?

MFA adds a second verification step beyond your password, significantly improving account security.

MFA Options

Setting Up MFA

  1. Go to Account > Security
  2. Click Setup MFA
  3. Choose Authenticator App
  4. Scan QR code with your app:
    • Google Authenticator
    • Microsoft Authenticator
    • Authy
    • 1Password
  5. Enter the 6-digit code
  6. Save backup codes

SMS Verification

  1. Go to Account > Security
  2. Click Setup MFA
  3. Choose SMS
  4. Enter phone number
  5. Verify with code sent to phone
  6. Save backup codes

Backup Codes

After setting up MFA, you receive backup codes:
  • Store securely - These are one-time use
  • Print or save - Keep in safe place
  • Use when needed - If you lose device access
  • Generate new - If you run out

Using MFA at Login

  1. Enter email and password
  2. When prompted, enter MFA code
  3. Code from authenticator app or SMS
  4. Optionally “Remember this device”

Disabling MFA

  1. Go to Account > Security
  2. Click Disable MFA
  3. Enter your password to confirm
  4. MFA is removed
Note: Your organization may require MFA. If so, you cannot disable it.

MFA Setup Page

Initial MFA Setup

If required during login:
  1. After password, you’re redirected to /mfa/setup
  2. Choose MFA method
  3. Complete setup process
  4. Continue to dashboard

MFA Verification

When logging in with MFA:
  1. Enter credentials
  2. Redirected to /mfa/verify
  3. Enter code from app or SMS
  4. Access granted

Session Management

Active Sessions

View your active login sessions:
  1. Go to Account > Security
  2. Scroll to Active Sessions
  3. See list of devices/browsers

Session Details

Ending Sessions

To log out from a specific device:
  1. Find session in list
  2. Click End Session
  3. That device is logged out
To log out everywhere:
  1. Click End All Sessions
  2. All devices logged out
  3. You’ll need to log in again

Security Recommendations

Password Best Practices

  • Use unique password for Taskr
  • Don’t share your password
  • Change if you suspect compromise
  • Use a password manager

MFA Best Practices

  • Enable MFA immediately
  • Use authenticator app over SMS
  • Save backup codes securely
  • Keep authenticator app updated

Session Best Practices

  • Log out on shared devices
  • Review sessions periodically
  • End unfamiliar sessions
  • Report suspicious activity

Troubleshooting

Common Issues

Account Locked

If your account is locked:
  1. Wait 15 minutes and try again
  2. Use password reset if needed
  3. Contact administrator if issue persists

MFA Recovery

If you lose access to MFA device:
  1. Use a backup code
  2. Contact administrator
  3. Admin can reset MFA
  4. Set up MFA again

Organization Security Policies

Your organization may enforce: Check with your administrator for specific policies.

Security Notifications

You may receive notifications for:
  • New device login
  • Password changed
  • MFA settings changed
  • Failed login attempts
  • Suspicious activity
Configure notification preferences in Account > Notifications.
Back to Account Overview | Back to Documentation Index