Skip to content
English - United States
  • There are no suggestions because the search field is empty.

User Guide: Administrator Playbook to Support Smartwebs Multi-Factor Authentication (MFA) 

This guide provides administrative and management users of Smartwebs with consistent procedures for assisting users before, during, and after the rollout of Multi-Factor Authentication (MFA) in Smartwebs.

Audience: Smartwebs Administrative Users

Purpose: This guide provides administrative and customer-facing admin users of Smartwebs with consistent procedures for assisting staff, board/committee member users through the rollout of Multi-Factor Authentication (MFA) in Smartwebs.


Section 1: Policy and Process Overview

What is MFA?

Multi-Factor Authentication (MFA) adds an additional layer of security by requiring users to verify their identity using a second authentication factor after entering their username and password.

This helps protect:

  • Customer data
  • Association information
  • Financial information
  • User accounts from compromised passwords

Please reference:

FAQ - What is Multi Factor Authentication (MFA) and Why Does it Matter?


What Will Users Experience?

When MFA is required or a user chooses to enroll:

  1. The user enters their username and password.
  2. If the user has not yet enrolled in MFA, Smartwebs prompts them to complete enrollment.
  3. The user selects one or more authentication methods.
  4. The user completes verification using their selected method.
  5. The user is logged into Smartwebs.

After MFA enrollment

Smartwebs now remembers successfully authenticated users on their trusted browser/device and network.

Users will not be prompted for MFA every time they log in when their trusted device and network are recognized.

A new MFA authentication may be required when:

  • A change in device or network is detected, or
  • 30 days have passed since the user's last MFA authentication.

This enhancement provides additional account security while reducing unnecessary MFA prompts during normal use.

Please reference:

User Guide - Enabling Multi-Factor Authentication


How Smartwebs MFA Works

MFA is configured at the Management company level and cannot be controlled individually by Association. This is due to the fact that many admin users are linked to multiple associations.  

Smartwebs supported the following MFA settings during the rollout:

Optional

Management users may self-enroll in MFA at their convenience.

Required

Management users must enroll in MFA before accessing Smartwebs.

Once MFA is enrolled, the user's authentication experience is designed to recognize a trusted browser/device and network. MFA will generally only be requested again when a change in device or network is detected or when the 30-day authentication period has expired.

MFA Required Date

MFA will become required for all Smartwebs accounts between August and October 2026, via a phased based rollout based upon product type.

MFA will be required for:

  • Global Admins
  • Limited Admins
  • Management Staff
  • Property Managers
  • Board Members
  • Committee Members

Administrators are encouraged to have users enroll before the required date to ensure a smooth transition.


Authentication Methods

Users may authenticate using one or more of the following methods:

  • Email Verification Code
  • Text Message Verification Code
  • Authenticator App, such as Google Authenticator or Duo

Users select their preferred authentication method during enrollment and may configure multiple available methods.

 


Trusted Authentication and MFA Prompts

Smartwebs uses trusted-device recognition to reduce unnecessary MFA prompts after a user has successfully authenticated.

When a user successfully authenticates

Smartwebs remembers the user's trusted browser/device and network.

The user can continue logging in without completing MFA again as long as the trusted authentication remains valid.

When will MFA be requested again?

The user may be prompted to authenticate again when:

  • They sign in from a different device.
  • A change in network is detected.
  • The 30-day authentication period has expired.
  • The trusted browser/device information is no longer available or recognized.

User Self-Service

Once enrolled, users can manage their MFA information in:

User Settings > Sign in & Security

From here they can:

  • Review their current MFA configuration
  • Update the email used for MFA
  • Update the phone number used for MFA
  • Change their preferred authentication method
  • Add available authentication methods

Note: Users will be prompted to re-enter their password to make changes to this area.

Important: Users should select Save after adding or changing their authentication method(s).


Global Admin Capabilities

Only a Global Admin can:

eset another user's MFA *requires user to reset password 
  • Force a user to enroll when MFA is Required

These actions are only available when the Management-level MFA setting is Required.

To change the Management-level MFA setting, contact Smartwebs Support.


Understanding "Reset MFA"

A Global Admin can select Reset MFA for an individual user when the Required setting is enabled and the user needs to complete or restart MFA enrollment.

Reset MFA may also be used when a user is enrolled in MFA but cannot access their authentication method or is unable to complete authentication.

Resetting MFA does two things:

  1. Resets the user's password.
    The user receives a Password Reset email.
  2. Removes the user's current MFA authentication.
    After creating a new password, the user is prompted to complete MFA enrollment before accessing Smartwebs.

Important: Always inform the user that resetting MFA will also reset their password before performing the reset.


Identity Verification

Always verify the identity of the caller before resetting MFA for another administrator, property manager, board member, or committee member.

  1. Follow your company's identity verification policies.
  2. Typically, this includes the caller correctly providing at least two identifiers associated with their Smartwebs account, such as:
    • Email
    • Full Name
    • UserID

Never ask the user for their password or MFA verification code.


When Does MFA Enrollment Occur?

Enrollment may occur from three starting points.

Scenario 1: MFA is Optional

MFA is set to Optional

User logs in

Navigates to User Settings > Sign in & Security

Selects Enable two-factor authentication

Adds one or more authentication methods:

  • Email
  • Text
  • Authenticator App

Completes verification using the preferred method

MFA enrollment is complete

Future MFA prompts are based on trusted device/network recognition and the 30-day authentication period


Scenario 2: MFA is Required

MFA is set to Required

User logs in

User receives a prompt to enroll

Adds one or more authentication methods:

  • Email
  • Text
  • Authenticator App

Completes verification using the preferred method

MFA enrollment is complete

Future MFA prompts are based on trusted device/network recognition and the 30-day authentication period


Scenario 3: Global Admin Performs Reset MFA

Dependent on Scenario 1 or Scenario 2 occurring first.

Global Admin performs Reset MFA for one user

Password Reset email is sent

User receives the link to create a new password

User creates a new password

User logs in

User receives a prompt to enroll

Adds one or more authentication methods:

  • Email
  • Text
  • Authenticator App

Completes verification

MFA enrollment is complete


Section 2: User FAQs

Why am I being asked to set this up?

Smartwebs has enabled Multi-Factor Authentication to provide additional protection for your account. Even if someone obtains your password, they won't be able to access your account without the second verification step. Once enrollment is complete, Smartwebs will remember your trusted device and network so you won't be prompted to authenticate every time you log in.


Why am I suddenly seeing this and I wasn't asked before?

Multi-Factor Authentication was recently enabled in Smartwebs to increase security and protect your account from unauthorized access. If this is your first login after MFA was enabled or your account is now required to use MFA, Smartwebs will prompt you to complete enrollment.


Do I have to authenticate every time I log in?

No. Once you successfully authenticate, Smartwebs will remember your trusted browser/device and network. You will generally only be prompted to authenticate again if a change in device or network is detected or 30 days have passed since your last MFA authentication.


Why am I being asked for MFA again?

Smartwebs may request MFA again when a change in device or network is detected or when 30 days have passed since your last MFA authentication. You may also be prompted again if your browser or device is no longer recognized as trusted.


Can you change my MFA settings?

Multi-Factor Authentication has been enabled for Smartwebs management users to help protect accounts from unauthorized activity and security threats. If you are unable to access your current authentication method, a Global Admin may assist with resetting your MFA after completing the required identity verification process.


Can I choose Email instead of Text?

Yes. Users may choose from the available authentication methods, including:

  • Email
  • Text Message
  • Authenticator App

Users may configure multiple methods and select their preferred method.


Can I change my MFA method later?

Yes. Users may update their preferred authentication method at any time by accessing User Settings > Sign in & Security.


Can I turn MFA off?

MFA is a company-wide security requirement when the Management-level setting is Required and cannot be disabled for individual users.


Is my password changing?

No. Your password does not change as part of normal MFA authentication.

MFA adds another verification step after entering your password.

Exception: If a Global Admin performs Reset MFA, the user's password is also reset and the user will receive a Password Reset email.


What happens if I use a different device?

Smartwebs may require MFA when you sign in from a different device because the new device is not recognized as a trusted device. After successfully authenticating, the new device can be recognized for future logins.


What happens if I use a different network?

Smartwebs may require MFA when a change in network is detected. After successfully authenticating, you can continue using Smartwebs without repeated MFA prompts unless another security condition requires authentication.


Why am I being prompted more frequently than expected?

Smartwebs is designed to remember successful MFA authentication for the trusted browser/device and network. You may be prompted again when a change in device or network is detected or after 30 days.

If you are being prompted for MFA on every login from the same device and network, contact Smartwebs Support for assistance.


Section 3: Troubleshooting Common Support Issues

"I'm stuck on the enrollment screen."

Verify:

  • Has the user selected an authentication method?
  • Are they receiving the verification code?
  • Are they completing verification?
  • Have they entered the required information correctly?
  • Have they saved their authentication method(s)?

Explain that enrollment must be completed before Smartwebs can be accessed when MFA is required.


"I reset my password and now it's asking me for MFA."

This is expected.

Resetting MFA also resets the user's password.

After the password is changed, Smartwebs immediately begins the MFA enrollment process.

The user must complete MFA enrollment before accessing Smartwebs when MFA is required.


"I changed my phone number."

If the user can still log in:

Direct them to:

User Settings → Sign in & Security

Update the phone number used for MFA.

If the user cannot log in:

A Global Admin may need to perform an MFA Reset so the user can enroll again.

Always verify identity before resetting MFA.


"I want to use an Authenticator App instead."

If the user can log in:

Go to:

User Settings → Sign in & Security

Select Authenticator App and complete enrollment.


"I never received my verification code."

Verify:
  • Correct email address
  • Spam/Junk folder checked
  • SMS signal available
  • Several minutes have passed
  • Correct authentication method was selected
  • Device has internet access
Troubleshooting:
  1. Wait 2–3 minutes.
  2. Click Resend Code once.
  3. Check the Junk/Spam folder if using email.
  4. Verify the email address on file.
  5. Verify the phone number if using SMS.
  6. Ensure the device has internet access.
Escalate if:
  • Multiple resend attempts fail.
  • Email delivery appears to be failing.
  • SMS delivery appears to be failing.
  • User account configuration appears incorrect.
  • Multiple users are experiencing the same issue.

"My code says it's invalid."

Verify:
  • The user entered the newest code.
  • An older code was not reused.
  • The code has not expired.
  • The device time is correct when using an Authenticator App.
Troubleshooting:

Ask the user to:

  • Request a new code.
  • Enter the newest code immediately.
  • Ensure device time is set automatically.

"I changed phones."

Determine:

Did the user:

  • Replace the phone?
  • Factory reset the phone?
  • Lose the device?
  • Switch to a different device?
Resolution:
  • Verify the user's identity.
  • If necessary, perform an MFA Reset.
  • Have the user re-enroll using the new device.

"I lost my phone."

Verify identity according to company policy before removing or resetting MFA.

After verification:

  • Reset MFA enrollment if necessary.
  • Guide the user through MFA setup on the new device.

"My authenticator app isn't working."

Verify:
  • Device time is set automatically.
  • Correct account is selected in the authenticator app.
  • Correct authenticator app is installed.
  • The Smartwebs account was not accidentally removed from the app.

If the issue cannot be resolved:

  • Verify the user's identity.
  • Reset MFA enrollment if appropriate.
  • Have the user complete enrollment again.

"I keep getting prompted every login."

This is not the intended normal experience after successful MFA authentication.

First verify:
  • Is the user using the same browser?
  • Is the user using the same device?
  • Has the user changed networks?
  • Are they using Incognito/Private Browsing?
  • Are browser cookies being cleared?
  • Are browser security settings preventing trusted-device information from being retained?
  • Has it been more than 30 days since the user's last MFA authentication?
Have the user:
  1. Use the same browser and device.
  2. Avoid Incognito/Private Browsing.
  3. Ensure cookies are enabled.
  4. Avoid clearing browser data between logins.
  5. Confirm whether the device or network has changed.
Escalate to Smartwebs Support if:

The user continues to receive an MFA prompt on every login while using the same device and network and none of the above conditions apply.

Provide:

  • User's email address
  • Browser being used
  • Device type
  • Whether the user is using a consistent network
  • Approximate time the issue began
  • Whether the issue occurs on every login
  • Any relevant screenshots, excluding live MFA codes

"I got a login approval I didn't request."

This may indicate that someone knows the user's password.

Advise the user to:
  1. Deny the authentication request.
  2. Change their password immediately.
  3. Contact Smartwebs Support if repeated unauthorized authentication attempts occur.

Do not ask the user to provide the MFA verification code.


"I'm locked out."

Verify:
  • User identity
  • MFA method
  • Number of failed attempts
  • What happens after the user enters their username and password

If appropriate:

  • Reset MFA enrollment.
  • Escalate if a security review is needed.

Troubleshooting Decision Tree

Cannot log in

Password accepted?

No

→ Password Reset

Yes

MFA enrollment completed?

No

Guide the user through enrollment

Choose:

  • Email
  • Text
  • Authenticator App

Verify

Login successful


Yes

Is MFA being requested?

No

→ Continue troubleshooting the login issue.

Yes

Is this a recognized device/network and within the 30-day authentication period?

Yes

Determine whether trusted-device information is being retained.

Check:

  • Same browser
  • Same device
  • Same network
  • Cookies enabled
  • Not using Incognito/Private Browsing
  • Browser data has not been cleared

Still prompting?

→ Escalate to Smartwebs Support.


No

MFA prompt is expected.

Complete MFA authentication

Login successful


User cannot complete MFA authentication

Troubleshoot:

  • Email
  • Text
  • Authenticator App

Still failing?

Verify identity

Reset MFA if appropriate

Password Reset

New MFA Enrollment


Section 4: Support Escalation Matrix

Issue Global Admin Smartwebs Support Smartwebs Engineering
User needs help enrolling  
User forgot password ✅ Reset password ✅ Reset password  
User wants a different MFA method ✅ Guide user ✅ Guide user  
User changed phone/email  
User cannot access MFA method ✅ Reset MFA after identity verification  
Force user to re-enroll  
MFA emails not sending  
MFA text messages not sending  
Authenticator App issue/bug  
User prompted for MFA every login despite using same device/network   ✅ if required
Multiple users affected  
Suspected MFA service outage  
Suspected security issue  

Section 5: Best Practices

When to Escalate to Smartwebs

Submit a ticket to Smartwebs Support if:

  • MFA service outage is suspected.
  • Email delivery is failing for multiple users.
  • SMS delivery is failing for multiple users.
  • Account corruption is suspected.
  • Authentication provider issues are suspected.
  • A user is repeatedly prompted for MFA on every login despite using the same device and network.
  • A security concern exists.
  • Multiple users are experiencing the same MFA issue.

Required Ticket Documentation

Always document:

  • Authentication method used
  • Browser and device, when relevant
  • Whether the user was using the same device/network
  • Troubleshooting performed
  • Whether the issue occurs on every login
  • Whether an MFA Reset was completed
  • Whether identity was verified
  • Outcome
  • Escalation details

Never include a user's password or live MFA verification code in a ticket.


Phone Call Template

Hello, thank you for reaching out.

I understand you're having trouble with Multi-Factor Authentication. I'll help get that resolved.

First, I'll look your account up in our system to verify your identity.

Can you please provide your name and the email address associated with your Smartwebs account and tell me what happens after you enter your username and password?

If you're being prompted for MFA, I'll also confirm whether you're using the same device and network you've used previously.

Thank you. Let's walk through a few quick steps together.


Email / Ticket Response

Hello,

Thank you for reaching out.

I'm sorry you're experiencing difficulty logging in with Multi-Factor Authentication.

Smartwebs is designed to remember successful MFA authentication on your trusted browser/device and network. You generally should not be prompted for MFA on every login.

If you're receiving an MFA prompt, please confirm:

  • Whether you're using the same device
  • Whether you're using the same browser
  • Whether you've changed networks
  • Whether you've recently cleared your browser data
  • Whether you're using Incognito/Private Browsing

You may also be prompted when 30 days have passed since your last MFA authentication.

If the issue continues, please reply with:

  • A screenshot of the message, if possible
  • The authentication method you're using
  • The browser and device you're using
  • Whether you're using the same network
  • The approximate time the issue occurred

Please do not include your password or MFA verification code in your response.

We'll be happy to continue assisting you.

Thank you,


MFA Reset Template

Hello,

We've reset your Multi-Factor Authentication enrollment.

Please note that resetting MFA also resets your Smartwebs password. You will receive a Password Reset email to create a new password.

After creating your new password and signing in, you'll be prompted to set up MFA again.

Please complete the enrollment process using your preferred authentication method.

If you experience any issues during setup, let us know and we'll be happy to assist.

Thank you,


Reassurance Statements

  • "I understand this adds an extra security step, and we're here to help make the process as easy as possible."
  • "Once you're enrolled, you should not have to authenticate every time you log in."
  • "Smartwebs remembers your trusted device and network after successful authentication."
  • "You may be asked to authenticate again if your device or network changes or after 30 days."
  • "We'll stay with you until you're able to sign in successfully."
  • "Thank you for your patience while we get this resolved."

Do Not Say

  • "We can bypass or disable MFA for you."
  • "You have to enter an MFA code every time you log in."
  • "Just keep trying."
  • "It's probably your phone."
  • "MFA always prompts when you log in."

Instead Say

  • "I'll walk through the setup with you."
  • "Let's verify where the process is stopping."
  • "Smartwebs should remember your trusted device and network after successful authentication."
  • "Let's determine why you're being prompted again."
  • "We'll identify the cause together."
  • "If needed, I can escalate this for further investigation."

Best Practices

  • Verify identity before discussing account details or performing an MFA Reset.
  • Use simple, non-technical language.
  • Ask one troubleshooting question at a time.
  • Avoid having users repeatedly request verification codes.
  • Document every MFA Reset.
  • Escalate potential security concerns immediately.
  • Never ask a user to share their MFA verification code.
  • Never ask a user for their password.
  • When troubleshooting repeated MFA prompts, confirm the user's device, browser, network, and browser privacy settings before escalating.
  • Do not tell users that repeated MFA prompts on every login are expected.

Notes

  • MFA is configured per Management company, not per Association.
  • MFA is required for applicable management users based on the Management company's rollout/enforcement date.
  • Users choose their preferred authentication method during enrollment.
  • After successful authentication, Smartwebs remembers the trusted browser/device and network.
  • Users generally will not be prompted for MFA on every login.
  • MFA may be requested again when a change in device or network is detected or when 30 days have passed since the user's last MFA authentication.
  • Browser settings such as Incognito/Private Browsing, cleared cookies, or other settings that prevent trusted-device information from being retained may result in additional MFA prompts.
  • Reset MFA also resets the user's password. Inform users before initiating or recommending this action.
  • Never ask a user for:
    • Their password
    • Their authentication code
    • A screenshot containing a live MFA code

MFA User Groups

MFA applies to:

  • Global Admins
  • Limited Admins
  • Management Staff
  • Property Managers
  • Board Members
  • Committee Members

MFA is not currently available for:

  • Residents
  • Vendors
  • Attorneys
  • Other third-party users

End of User Guide