User Guide: Administrator Playbook to Support Smartwebs Multi-Factor Authentication (MFA)
This guide provides administrative and customer facing staff who utilize Smartwebs, with consistent procedures for assisting users before, during, and after the rollout of Multi-Factor Authentication (MFA) in Smartwebs.
Audience: Smartwebs Administrative Users
Purpose: This guide provides administrative and customer facing staff who utilize Smartwebs, with consistent procedures for assisting users before, during, and after the rollout of Multi-Factor Authentication (MFA) in Smartwebs.
Section 1: Policy and Process Overview
What is MFA?
Multi-Factor Authentication (MFA) adds an additional layer of security by requiring users to verify their identity using a second authentication factor after entering their username and password.
This helps protect:
- Customer data
- Association information
- Financial information
- User accounts from compromised passwords
Please reference this article:
FAQ - What is Multi Factor Authentication (MFA) and Why Does it Matter?What Will Users Experience?
After MFA is enabled:
- User enters username and password.
- User is prompted to verify their identity.
- User enters the verification code or approves the authentication request.
- User is logged into Smartwebs.
- Users will asked to enroll their authentication method the first time they log in.
Please reference this article:
User Guide - Enabling Multi-Factor AuthenticationHow Smartwebs MFA Works
To date, Smartwebs' Multi-Factor Authentication (MFA) has been Optional for Smartwebs customers.
As a security enhancement, MFA will become Required for administrators and management users, beginning in August of 2026.
Three Management-wide options are available:
|
Setting |
Description |
Notes |
|
Disabled |
No users are prompted for MFA |
Default state |
|
Optional |
Management users may self enroll in MFA at their convenience |
Implementation Phase One 8/3/26 *all clients all tiers |
|
Required |
Every management user must enroll in MFA before accessing Smartwebs |
Implementation Phase Two 8/17/26 *applicable client tiers |
Authentication Methods
Users may authenticate using one of the following methods:
- Email Verification Code
- Text Message Verification Code
- Authenticator App (Google Authenticator, Duo, or another compatible app)
Users will select their preferred authentication method during enrollment and may set up all 3 or 2 options as available.
User Self-Service
Once enrolled, users can manage their MFA information in User Settings > Sign in & security:
From here they can:
- Review current MFA configuration
- Update email used for MFA
- Update phone number used for MFA
- Change preferred authentication method
Note: Users will be prompted to re-enter their password to make changes to this area.
Important! Be sure to hit Save after adding your Authentication method(s):
Global Admin Capabilities
Only a Global Admin can:
- Reset another user's MFA
- Force a user to enroll
- Note: these actions are only available if the Management level is set to Required
To change MFA settings (from Optional to Required) at the Management level, contact Smartwebs Support.
Understanding "Reset MFA"
A Global Admin can choose Reset MFA for individual user when the Required setting is enabled but the user has not logged in or setup MFA. Additionally, this can be used to reset an account who is enrolled in MFA but cannot access their authentication method and/or is locked out due to unsuccessful attempts to authenticate.
Resetting MFA does two things:
- Resets the user's password: The user receives a Password Reset email.
- Removes their current MFA authentication: After creating a new password, they are immediately prompted to complete MFA enrollment before accessing Smartwebs.
Identity Verification
Always verify the identity of the caller before resetting MFA for another administrator, property manager, board, or committee member.
- Follow your company policies for identity verification.
- Typically this includes the caller correctly providing at least 2 identifiers associated with their Smartwebs account:
- Full Name
- UserID
When Does MFA Enrollment Occur?
Enrollment may occur from three starting points:
Scenario 1
MFA is set to Opt-In
↓
User logs in
↓
Navigates to user Settings > Sign in & Security
↓
Clicks Enable two-factor authentication
↓
Adds one or more Two-factor Methods: Email, Text, Authenticator App
↓
Completes verification using preferred method
↓
Logs in
Scenario 2
MFA is set to Required
↓
User logs in
↓
Receives prompt to enroll
↓
Adds one or more Two-factor Methods: Email, Text, Authenticator App
↓
Completes verification using preferred method
↓
Logs in
Scenario 3
*Dependent on scenario 1 or 2 occurring first*
↓
Global Admin performs Reset MFA for one user at a time
↓
Password Reset Email is sent
↓
User receives link to create new password
↓
User logs in
↓
Receives prompt to enroll
↓
Adds one or more Two-factor Methods: Email, Text, Authenticator App
↓
Completes verification using preferred method
Section 2: User FAQs
Why am I being asked to set this up?
Smartwebs has enabled Multi-Factor Authentication to provide additional protection for your account. Even if someone obtains your password, they won't be able to access your account without the second verification step. Once enrollment is complete, you'll use your preferred verification method whenever authentication is required.
Why I am suddenly seeing this and I wasn't asked before?
Multi-Factor Authentication was recently enabled in Smartwebs to increase security and protect your account from unauthorized access. Since this is your first login after the update, the system is prompting you to complete enrollment.
Can you change my MFA settings?
Multi-Factor Authentication has been enabled for HOA Management/Staff and Board/Committee member users of Smartwebs, to protect your account from unauthorized activity and security threats. If you are unable to access your current authentication method, after a quick identity verification process, we (Global Admin) can assist with resetting your MFA which will send you a system prompt to change your password and select your preferred MFA method(s).
Can I choose Email instead of Text?
Yes. Users may choose from three methods, or set up all three and select their preferred method:
- Text Message
- Authenticator App
Can I change my MFA method later?
Yes. Users may update their preferred authentication method at any time by accessing User Settings > Sign in & Security.
Can I turn MFA off?
MFA is a company-wide security requirement and cannot be disabled for individual users.
Is my password changing?
No. Passwords remain the same.
MFA simply adds another verification step after entering your password.
Do I have to authenticate every login?
This depends on:
- Browser/device recognition
- Company security settings
- Whether cookies were cleared
- Incognito/private browsing
- Device changes
Section 3: Troubleshooting Common Support Issues
"I'm stuck on the enrollment screen."
Verify:
- Has the user selected an authentication method?
- Are they receiving the code?
- Are they completing verification?
- Have they entered their password after verification?
Explain that enrollment must be completed before Smartwebs can be accessed when MFA is required.
"I reset my password and now it's asking me for MFA."
This is expected.
Resetting MFA also resets the password.
After the password is changed, Smartwebs immediately begins the MFA enrollment process.
"I changed my phone number."
If they can still log in:
Direct them to:
User Drawer → Sign-In & Security
Update their phone number.
If they cannot log in:
A Global Admin may need to perform an MFA Reset so the user can enroll again.
"I want to use an Authenticator App instead."
If they can log in:
Go to:
User Drawer → Sign-In & Security
Select Authenticator App and complete enrollment.
"I never received my verification code."
Verify
- Correct email address?
- Spam/Junk folder checked?
- SMS signal available?
- Delay of several minutes?
- Authenticator app selected instead of email?
Troubleshooting
- Wait 2–3 minutes.
- Click Resend Code once.
- Check Junk/Spam folder.
- Verify email address on file.
- Verify phone number if using SMS.
- Ensure device has internet access.
Escalate if
- Multiple resend attempts fail.
- Email delivery appears to be failing.
- User account configuration appears incorrect.
"My code says it's invalid."
Verify
- User entered newest code.
- Older code wasn't reused.
- Code hasn't expired.
- Device time is correct (Authenticator apps).
Troubleshooting
Ask the user to:
- Request a new code.
- Enter the newest code immediately.
- Ensure device time is set automatically.
"I changed phones."
Determine
Did they:
- Replace the phone?
- Factory reset?
- Lose the device?
Resolution
- Remove existing MFA registration (Reset MFA).
- Have the user re-enroll.
- Verify identity before resetting MFA.
"I lost my phone."
Verify identity according to company policy before removing or resetting MFA.
After verification:
- Reset MFA enrollment.
- Guide user through setup on new device.
"My authenticator app isn't working."
Verify:
- Device time is automatic.
- Correct account selected.
- Correct app installed.
- Account wasn't accidentally removed.
- If needed:
Reset MFA enrollment.
"I keep getting prompted every login."
Possible causes:
- Private browsing
- Cookies cleared
- Browser security settings
- Different browsers
- Different devices
Have user:
- Use same browser.
- Enable cookies.
- Avoid Incognito mode.
"I got a login approval I didn't request."
This may indicate someone knows their password.
Advise user:
- Deny the request.
- Change password immediately.
- Escalate back to Smartwebs Support if repeated attempts occur.
"I'm locked out."
- Verify identity
- MFA method
- Number of failed attempts
If appropriate:
- Unlock account
- Reset MFA enrollment
- Escalate if security review needed
Troubleshooting Decision Tree
Cannot log in
↓
Password accepted?
No
→ Password Reset
Yes
↓
Already enrolled?
No
↓
Guide through enrollment
↓
Choose
• Text
• Authenticator App
↓
Verify code
↓
Login successful
Already enrolled?
Yes
↓
Receiving verification?
No
↓
Troubleshoot Email/Text/App
↓
Still failing?
↓
Reset MFA
↓
Password Reset
↓
New Enrollment
Section 4: Support Escalation Matrix
|
Issue |
Global Admin |
Smartwebs Support |
Smartwebs Engineering |
|
User needs help enrolling |
✅ |
✅ |
|
|
User forgot password |
✅(reset password) |
✅(reset password) |
|
|
User wants different MFA method |
✅ (guide user) |
✅ (guide user) |
|
|
User changed phone/email |
✅ |
✅ |
|
|
Force user to re-enroll |
✅ |
✅ |
|
|
MFA emails not sending |
|
✅ |
✅ |
|
MFA text messages not sending |
|
✅ |
✅ |
|
Authenticator App bug |
|
✅ |
✅ |
|
Multiple users affected |
|
✅ |
✅ |
Section 5: Best Practices
When to Escalate to Smartwebs
Submit a ticket to Smartwebs Support if:
- MFA service outage suspected
- Email delivery failure for multiple users
- Account corruption suspected
- Authentication provider issue
- Security concern
Required Ticket Documentation
Always document:
- Authentication method used
- Troubleshooting performed
- MFA reset completed?
- Identity verified?
- Outcome
- Escalation details
Phone Call Template
Hello, thank you for reaching out.
I understand you're having trouble with Multi-Factor Authentication. I'll help get that resolved.
First, I'll look your account up in our system to verify your identity.
Can you please provide your name and the email address associated with your Smartwebs account and tell me what happens after you enter your username and password?
Thank you. Let's walk through a few quick steps together...
Email / Ticket Response
Hello,
Thank you for reaching out.
I'm sorry you're experiencing difficulty logging in with Multi-Factor Authentication.
Based on the information provided, please try the following:
• Request a new verification code. • Use only the most recent code received. • Check your Spam or Junk folder if using email verification. • Ensure your device has an internet connection.
If the issue continues, please reply with:
- A screenshot of the message (if possible)
- The authentication method you're using
- The approximate time the issue occurred
We'll be happy to continue assisting you!
Thank you,
MFA Reset Template
Hello,
We've reset your Multi-Factor Authentication enrollment.
The next time you sign in, you'll be prompted to set up MFA again.
Please complete the enrollment process using your preferred authentication method.
If you experience any issues during setup, let us know and we'll be happy to assist.
Thank you,
Reassurance Statements
Use these when customers are frustrated:
- I understand this adds an extra step, but it's designed to better protect your account.
- Once you're enrolled, the process is typically very quick.
- We'll stay with you until you're able to sign in successfully.
- Thank you for your patience while we get this resolved.
- "We can bypass/disable MFA for you."
- "Just keep trying."
- "It's probably your phone."
- I'll walk through the setup with you.
- Let's verify where the process is stopping.
- We'll identify the cause together.
- If needed, I can escalate this for further investigation.
Best Practices
- Verify identity before discussing account details or performing MFA reset.
- Use simple, non-technical language.
- Ask one troubleshooting question at a time.
- Avoid having users repeatedly request verification codes.
- Document every MFA reset.
- Escalate potential security concerns immediately.
- Never ask a user to share their MFA verification code.
- Never ask a user for their password.
Notes
- MFA is configured per Management company, not per Association.
- While Global Admin previously dictated whether MFA is Disabled, Optional, or Required, it has become a requirement for all Management users to protect all accounts from unauthorized access.
- Users choose their preferred authentication method during enrollment.
- Reset MFA also resets the user's password. Inform users before initiating or recommending this action.
- Never ask a customer for:
- Their password
- Their authentication code
- A screenshot containing a live MFA code
End of User Guide