Security & 2FA
Account security matters. Resplendent Data provides Two-Factor Authentication (2FA) and session management to protect your data.
Two-Factor Authentication (2FA)
Section titled “Two-Factor Authentication (2FA)”We recommend enabling 2FA for all users. It requires a 6-digit code from your phone every time you sign in.
Setting up 2FA
Section titled “Setting up 2FA”- Click your User Profile menu (top right)
- Select Security
- Click Enable Two-Factor Authentication
- Scan the QR code with your authenticator app (Google Authenticator, Microsoft Authenticator, Authy, etc.)
- Enter the 6-digit verification code
- Save your recovery codes!
Using 2FA recovery codes
Section titled “Using 2FA recovery codes”If you lose your device:
- On the 2FA login screen, select Use Recovery Code
- Enter one of your unused 10-digit codes
- Once logged in, disable and re-enable 2FA to set up your new device
If you have no recovery codes and cannot log in, ask an admin to disable 2FA for your account from Settings → Team & Access. You can then re-enable it from your profile.
Switching authenticator devices
Section titled “Switching authenticator devices”- Open Profile → Security
- Click Disable Two-Factor Authentication
- If your Company requires 2FA, you are immediately sent back to the setup flow
- Scan the new QR code and save the new recovery codes
Require 2FA for the Company
Section titled “Require 2FA for the Company”Company admins can require 2FA for all email/password users:
- Go to Settings → Team & Access
- In the Security section, turn on Require two-factor authentication
- Confirm the change
When this is on:
- Email/password users without 2FA must complete setup before using the app
- Microsoft SSO users are not required to set up Resplendent 2FA
- Users can still disable and re-enable 2FA to switch devices; they are redirected into setup again immediately
- Admins can still disable another user’s 2FA to recover lockouts; that user must re-enroll before continuing
You must already have 2FA enabled on your own email/password admin account (or sign in with Microsoft SSO) before you can turn the Company requirement on.
Session management
Section titled “Session management”- Auto-logout: Sessions expire after inactivity
- Active sessions: View all devices logged into your account from the Security tab. Revoke access to unrecognized devices instantly.
Password requirements
Section titled “Password requirements”Passwords must:
- Be at least 10 characters
- Include uppercase, lowercase, numbers, and symbols
- Not be a previously used password
Enterprise security features
Section titled “Enterprise security features”Higher tiers offer additional protections:
Single Sign-On (SSO)
Section titled “Single Sign-On (SSO)”Available on Business and Starship plans. Log in with your existing identity provider (Okta, Azure AD, Google Workspace).
Audit Logs
Section titled “Audit Logs”Available on Business and higher. Detailed history of every action in your account: data exports, configuration changes, user access.