FAQ: Two-factor Authentication on login:πŸ†•

To better protect your club's sensitive data, Xplor Gym is introducing two-factor authentication (2FA) on the back office. Every fortnight, you will need to enter your usual password, followed by a unique code received by SMS or email. This code guarantees that you are indeed the account holder, reinforcing security and blocking any unauthorised access, even if the password has been compromised.

πŸ‘‰ This article answers any questions you may have about this new safety measure.

⚠️ Essential check before installing

Before activating two-factor authentication, make sure that each back office user has at least a valid email address on their user file. It is also strongly recommended to enter a telephone number.

Without this information, users will not be able to receive their connection code and may be blocked from accessing the site.

πŸ”Why are you introducing two-factor authentication in Xplor Gym?

Two-factor authentication (2FA) has been introduced to strengthen the security of access to the Xplor Gym back office. Today, the data managed in the software (members' personal information, means of payment, invoicing data, etc.) is sensitive. It is therefore essential to protect it effectively.

πŸ” By adding a validation step by SMS or email, even if a password is stolen or guessed, unauthorised access is blocked.

This measure is part of an overall approach to securing digital tools and complying with best practice in data protection.

πŸ“‹ What should you do before setting up two-factor authentication for a back office user?

Before activating two-factor authentication, make sure that each user in your back office has at least a valid email address, and ideally also a telephone number in their profile.

πŸ‘‰ One of these two methods (SMS or email) will be used to send the verification code when you log in. Ideally, it is recommended that you fill in both, to ensure flexibility and continuity of access should the need arise.

A quick check today = a smooth transition tomorrow!

⚠️ Is 2FA compulsory or optional for the back office?

Two-factor authentication (2FA) will become compulsory for all users of the Xplor Gym backoffice.

πŸ”„ A gradual roll-out phase is planned for the summer of 2025, starting with volunteer clubs to test and support the activation of the system.

πŸ“… Before the end of July 2025, the 2FA will be activated for all clubs using Xplor Gym, without exception.

πŸ“… When will 2FA be activated?

Two-factor authentication will be activated for all clubs before the end of July 2025.

The roll-out will be gradual and communications will be sent out in advance.

πŸ‘₯ Who in the club is affected by this measure?

All backoffice users are affected by the introduction of two-factor authentication. This includes administrator profiles, managers, coaches or any other person with access to the Xplor Gym backoffice.

πŸ‘‰ This measure does not affect your clients: they will not be impacted in the member area or on the application.

βš™οΈ How to activate two-factor authentication for a back office user?

You won't have to do a thing. Two-factor authentication will be automatically activated for all users.

πŸ“© A notice will be sent to you in advance so that you can prepare yourself calmly.

πŸ“§ What should you do if a user doesn't have a telephone number listed in the back office?

Don't worry: if a user doesn't have a telephone number, they can receive the verification code by email.

πŸ‘‰ It is therefore essential to ensure that the email address given in the user file is correct and accessible.

πŸ” Do you need to enter a code each time you log on?

No. Once you have entered the code, it will remain in memory for 15 days on the device you are using. You will simply have to re-enter it once this period has elapsed, or if you reconnect from another device or browser.

πŸ§‘β€πŸ’» What if two people log on to the same computer (e.g. a front-desk agent)?

In this case, each user will receive a check when they log on for the first time:

  • The first person enters their code, which remains active for 15 days.
  • When changing user, the second person will also have to enter their own code.

πŸ” Validation is linked to the user and the computer. Each employee will therefore have to validate his or her identity, even if the computer is shared. And when a user defines the computer as a β€˜trusted device’, they no longer have to validate their authentication for 15 days.  

πŸ” Best practice if sharing a computer:

Never save the password in the browser
➀ Avoid clicking on β€˜Save password’ in Chrome, Firefox or Safari. This would allow the other person to log in for you without your authorisation.

Always log out after use
➀ Remember to log out manually at the end of each session to prevent unauthorised access.

⏱ When is a check request launched?

A check request is launched in the following cases:

  • βœ… If you are connecting from a new device or browser,
  • βœ… If you change users on a shared device and one or other has not validated their connection for more than 15 days.

⏳ Once the check has been carried out, it remains valid for 15 days for each user, on each device used.

❌What should you do if a user doesn't receive the code?
  1. Check contact details
    Make sure that the user's email address and mobile phone number are correct and up to date.
  2. Send code back
    Click on the β€˜I have not received the code’ or β€˜Start the procedure again’ button to generate a new shipment.
  3. Contact Support
    If the problem persists, please contact our support team for assistance.
  4. Good to know:
    To avoid this type of blockage, inform your users that it is essential not to unsubscribe from emails and text messages sent by Xplor Gym, particularly those containing login codes.
  •  
πŸ‘‰Why are management exports subject to 2FA?

Your management exports may contain client data that could be misused for fraudulent purposes. A set of around twenty exports is now protected by two-factor authentication. They are listed in the following article.

 

Was this article helpful?
0 out of 0 found this helpful
Submit a request

Comments

0 comments

Please sign in to leave a comment.