Overview
Two Factor / Multi‑Factor Authentication (2FA / MFA) can be enabled as a feature for users in BrightPay. This feature is currently optional but strongly recommended to help protect your data.
2FA / MFA adds a second layer of protection to re‑confirm the identity of users logging into BrightPay through an internet browser. This improves security, protects against fraud, and lowers the risk of data breaches, as users can access sensitive employer and employee data in BrightPay with an increased security layer.
Important change from 1 October 2026
From 1 October 2026, 2FA / MFA will be mandatory for all Team members on a BrightPay Organisation.
- If 2FA / MFA has not been switched on for your Organisation by this date, it will be enabled by the BrightPay Development team.
- In this case, email will be set as the default method for receiving the 6‑digit security code for all affected Team members. (Please check your spam/junk folder if you do not receive it.)
We recommend that Organisation owners and administrators enable and configure 2FA / MFA in advance of this date, and encourage Team members to choose their preferred verification method.
Enabling 2FA / MFA at Organisation level
To enable 2FA / MFA on a BrightPay Organisation, an Owner or an Administrator must:
- Sign into the BrightPay Organisation.
- Select My Organisation.
- Select Manage Team Members.
- Choose one of the following options:
- Two-Factor Authentication is Optional – 2FA / MFA is available but not required for Organisation members (current default behaviour, until 1 October 2026).

- Require 2FA for organisation members – 2FA / MFA is required for all Team members on the Organisation.

When the ‘Require 2FA for organisation members’ option is selected and saved, any Team member on the BrightPay Organisation who signs into BrightPay will be required to enter a 6‑digit security code.
If the user has no method of receiving the 6‑digit code set up, by default it will be sent to the team member’s email address. (Please check your spam folder if you do not receive it.)
Enabling 2FA / MFA for an individual Team member
If required, each Team member can set up the specific method to receive the 6‑digit code for their individual profile. To set this up, the Team member must be logged into BrightPay.
- Select the profile icon in the top right-hand corner and choose Manage my Bright ID.

- Under the Security tab, select 2FA Settings.

- Under Choose your preferred 2FA method, select one of the following:
- Authentication App (preferred and most secure method)
Use an authentication app that can generate a personal one-time code. Entering the code will be required to successfully log into BrightPay with your Bright ID. - Text Message
Receive a text message containing your code to your mobile phone whenever you try to log into BrightPay with your Bright ID. Entering the code will be required to log in successfully. - Email
Receive an email containing a code to your email address whenever you try to log into BrightPay with your Bright ID. Entering the code will be required to log in successfully.

Note: To change the 2FA method once set, please select the profile icon in the top right-hand corner and select Manage My Bright ID.
Under the Security tab, select 2FA Settings. Then choose the new 2FA method that you would prefer from the three options available. Save the settings.
FAQs
Q. How do I reset my two-factor / multi‑factor authentication (2FA / MFA) on my Bright ID?
A. For security and GDPR reasons, 2FA / MFA reset requests must come from an authorised contact. Please follow the instructions that match your role:
- Employee
Please contact your payroll processor or manager and ask them to email our support team to confirm that you would like your 2FA / MFA to be reset. - Manager
Please contact your payroll processor and ask them to email our support team to confirm that you would like your 2FA / MFA to be reset. - Team member / Admin / Payroll Processor
Please contact your business owner or CEO and ask them to email our support team to confirm that you need your 2FA / MFA to be reset. - Client portal user (User / Super User)
Please contact your payroll processor and ask them to email our support team to confirm that you would like your 2FA / MFA to be reset.
Additional security notes
Browser settings will usually remember user login credentials. If you wish to be prompted to enter login credentials each time, you will need to enable the 2FA / MFA settings (this applies to all users including employees).
For greater security, BrightPay Cloud supports 2FA / MFA for Employee Self Service Portal users. To enable 2FA / MFA:
- Go to Employee Portal > Security Settings.
- Follow the instructions to activate two-factor / multi‑factor authentication.
This ensures employees cannot access their portal without an additional verification step, even if their browser remembers login sessions.
Note: BrightPay will not automatically log a user out after a period of inactivity on screen.
Comments
0 comments
Article is closed for comments.