How to add an authenticator application to your SocialNote account, sign in securely, and retain access with recovery codes.
Two-factor authentication adds a second verification step to password-based sign-in. After entering your email address and password, you enter a current six-digit code from an authenticator application.
| Factor | What it verifies |
|---|---|
| Your password | Something you know. |
| Authenticator code | Access to an authenticator you enrolled. |
| Recovery code | A one-time backup when the authenticator is unavailable. |
Two-factor authentication may be available in Account Security before your district requires it. When required enrollment is enabled, SocialNote will guide users through setup before they continue into the platform.
You will need a standards-compatible TOTP authenticator application. Common choices include Google Authenticator, Microsoft Authenticator, 1Password, and other applications that support time-based one-time passwords.
The QR code and text setup key can enroll an authenticator. Do not photograph, email, paste into support messages, or share either one.
If enrollment is optional, open Settings → Account Security and choose Enable two-factor authentication. SocialNote may ask you to confirm your password before displaying the setup screen.
Scanning the QR code alone does not activate two-factor authentication. Enter a current six-digit code and wait for SocialNote to confirm the enrollment.
When your district enables required two-factor authentication, an unenrolled user is directed to Set up two-factor authentication after signing in and confirming their password. Complete enrollment to continue to the SocialNote dashboard.
Once required by the district, users cannot cancel or disable enrollment. This prevents an account from returning to password-only sign-in while the requirement is active.
Authenticator codes change regularly. If a code is rejected, confirm that you selected the SocialNote entry, wait for the next code, and try again. Also check that the device running the authenticator has the correct date and time.
Recovery codes are backup credentials for situations when your authenticator is unavailable. Each recovery code can be used only once.
Open Settings → Account Security and choose Generate new codes. You may be asked to confirm your password. Store the new codes immediately; every code from the previous set stops working.
Contact your district’s authorized SocialNote administrator or support contact. Expect the organization to verify your identity before requesting an enrollment reset.
After an authorized reset:
An administrator should never ask you to read or send an authenticator code, recovery code, QR code, or setup key. Recovery replaces the old enrollment rather than retrieving its secrets.
Use Settings → Account Security to see whether two-factor authentication is active, copy the current recovery codes, or generate a replacement set.
If two-factor authentication is optional, Account Security may also allow you to disable it after password confirmation. Disabling returns the account to password-only sign-in and invalidates the current recovery codes. When the district requires two-factor authentication, the disable option is not available.
| Do | Do not |
|---|---|
| Use an organization-approved authenticator and password manager. | Share codes, setup keys, QR codes, or recovery codes with anyone. |
| Verify that a sign-in prompt follows an action you initiated. | Approve or answer an unexpected request for account verification. |
| Generate new recovery codes if their storage may have been exposed. | Store recovery codes in SocialNote student records or ordinary email. |
| Contact your administrator promptly after losing a device. | Ask another person to enroll their authenticator on your account. |
| Action | Who |
|---|---|
| Enroll an authenticator | Each user for their own account. |
| Use or regenerate recovery codes | Each enrolled user for their own account, after any required password confirmation. |
| Disable optional two-factor authentication | The account owner when district enforcement is not active. |
| Require two-factor authentication | Authorized SocialNote deployment administrators working with the district. |
| Reset a lost enrollment | An authorized administrator or support operator after following the organization’s identity-verification process. |