Multi-factor authentication | BondiByte NDIS Software
Security & Identity

MFA where it matters.

Protect sign-ins with a second check from a standard authenticator app, then require it for the accounts that matter most. A stolen password on its own gets an attacker nowhere.

Multi-factor authentication

What you get with Multi-factor authentication.

  • App-based multi-factor auth

    Add a second factor with standard authenticator apps for stronger sign-in security.

  • Admin-portal MFA policy

    Require MFA for admin access, so your most powerful accounts are the best protected.

  • Session revocation

    End a session the moment access should stop, so leavers lose access promptly.

Why it exists

The problem it solves.

Passwords leak. They get reused across sites, phished, and guessed, and for an NDIS provider a compromised admin login means client records, rosters and financial details. Multi-factor authentication (MFA) adds a second check at sign-in, a rolling code from an app on your phone, so a stolen password on its own gets an attacker nowhere.

How it works

1

Enrol in minutes

Scan a code with any standard authenticator app, such as Microsoft Authenticator or Google Authenticator, and confirm with your first six-digit code. No special hardware needed.

2

Sign in with a second check

After your password, enter the current code from your app. Codes change every 30 seconds, so an old code is worthless.

3

Keep recovery codes safe

Setup issues one-time recovery codes for the day your phone is lost or replaced. You can regenerate a fresh set whenever you need.

4

Require it for admin access

Once your own MFA is working, an owner can require MFA for everyone opening the Admin Portal, so the most powerful accounts carry the strongest protection.

5

See it working

MFA activity, including setup, successful checks and failed attempts, is recorded so unusual activity is visible.

What you can do.

Works with any standard authenticator app

BondiByte uses the open authenticator standard, so Microsoft Authenticator, Google Authenticator, 1Password and similar apps all work.

Recovery codes

One-time codes issued at setup and regenerable at any time, so a lost phone is an inconvenience rather than a crisis.

Admin Portal MFA policy

Require MFA for everyone with manager, admin or owner access to the Admin Portal, in one setting.

Gentle rollout

MFA is optional per person until you require it, with an in-app reminder nudging people to enrol.

An MFA activity trail

Enrolments, checks and failures are recorded, giving you visibility of how sign-in security is actually being used.

How it connects.

  1. Password sign-in
  2. MFA check for enrolled accounts
  3. Role-based access takes over
  4. Policy set in Security settings
  5. Identity-managed teams can use Microsoft SSO instead

You stay in control.

Require MFA for the Admin Portal

One owner-held setting gates Admin Portal access behind MFA. It stays locked until your own MFA works, so you can never require what you have not tested.

Session timeout policy

Choose how long a sign-in stays valid before people must sign in again. Applies to new sign-ins after you save.

End access promptly

When someone leaves, deactivating them and revoking their sign-in sessions cuts access immediately, not at their next timeout.

Staff-day access undisturbed

The Admin Portal policy does not change staff-facing portal sign-in, so tightening admin security never disrupts shift-day access for support workers.

Learn how to use this feature.

Frequently asked questions.

Which authenticator apps can we use?

Any app that follows the standard authenticator approach: Microsoft Authenticator, Google Authenticator, 1Password and others all work.

What happens if someone loses their phone?

They sign in with one of the recovery codes saved at setup, then enrol their new device. Recovery codes can be regenerated at any time, so keep them somewhere safe.

Does BondiByte MFA apply to Microsoft SSO sign-ins?

No. SSO sessions are governed by your identity provider's own policies, such as Microsoft Entra conditional access. BondiByte MFA protects password sign-ins.

Is MFA compulsory?

It is your choice. Individuals can enrol at any time, and an owner can make it mandatory for Admin Portal access once their own MFA is working.

Will requiring MFA lock anyone out?

The policy is deliberately sequenced: you must enrol and verify your own MFA before you can require it for others, which prevents the classic self-lockout.

See Multi-factor authentication in BondiByte

Start your free trial, or book a demo to see it with your own operation in mind.

Start free trial