Securing your account with two-factor authentication

Manage your own security at: Account settings → Security (from the menu under your name)


Two-factor authentication (2FA) adds a second step when you sign in. As well as your password, you enter a one-time code from an authenticator app on your phone. This protects your account even if your password is compromised.


Setting up two-factor authentication


You'll need an authenticator app such as Google Authenticator or Microsoft Authenticator.


  1. Open Account settings from the menu under your name, and select the Security tab
  2. Start the two-factor setup
  3. Scan the QR code with your authenticator app, or enter the secret manually
  4. Enter the 6-digit code from the app and select Verify and enable


Two-factor authentication is now active on your account.


Signing in with two-factor authentication


Once 2FA is enabled you'll be asked for a code from your authenticator app each time you sign in, after entering your password.


If you lose access to your authenticator app, contact us at support@simchat.ai.


Changing your password


You can change your password from the same Security tab, using Change password.


Resetting or disabling two-factor authentication


From the Security tab you can:


  • Reset authenticator - set 2FA up on a new device, for example if you change phones
  • Disable - turn off 2FA, if your organisation allows it


Both actions ask you to confirm your password.


Requiring two-factor authentication for staff


This section is for organisation owners and administrators, and is set at Organisation settings → Security.


Turn on Require two-factor authentication for staff to make 2FA compulsory.


When this is enabled:


  • Everyone with a staff role must set up 2FA before they can use SimChat - owners, administrators, assistant administrators, cohort leads, authors, assessors and viewers
  • Learners are not affected
  • Staff cannot disable their own 2FA while the requirement is on. They can still reset it to a new device


If you turn the requirement on and don't yet have 2FA yourself, you'll be taken straight to the setup page.


If your organisation uses single sign-on, 2FA is normally handled by your identity provider instead. See Single sign-on and LMS integration.

Updated on: 07/09/2026

Was this article helpful?

Share your feedback

Cancel

Thank you!