Skip to main content

Multi-factor authentication in Preno

What multi-factor authentication is, why Preno is making it required, and what you need to do.

Written by Kevin Soo

Your Preno account holds your bookings, your guests' personal details and your payment records. Multi-factor authentication (MFA) keeps all of that protected even if someone gets hold of your password.

MFA means signing in takes two things instead of one: your password, plus a six-digit code from an app on your phone. A stolen password on its own is no longer enough to get into your account.

What's changing

MFA has been optional in Preno. It is becoming required for every user, rolled out region by country:

  • 1 September — New Zealand

  • 8 September — Australia

  • 15 September — United Kingdom and all other regions

From your country's date, you'll be asked to set up MFA the next time you sign in. You won't be able to skip it.

We recommend getting this set up early. It takes about five minutes at a time that suits you to avoid disruption when MFA enforcement starts.

Who this applies to

Every user on an active Preno account (owners, managers, front desk, housekeeping etc). Free trial accounts are exempt until your subscription starts.

Why we're doing this

Accommodation businesses are being targeted directly. Attackers get into a property's systems, then message guests posing as the property and ask them to pay again or re-enter their card details. Hundreds of hotels, motels and guesthouses across dozens of countries have been caught up in these reservation-hijacking scams, and small properties are hit as often as large chains.

Nearly all of these attacks start the same way — with a stolen or guessed password. MFA closes that door. It is the single most effective step you can take to protect your business, your guests and your reputation.

As these attacks escalate, we don't think it's responsible to leave this optional. MFA is becoming the standard across every Preno account, so every property has the same level of protection.

What to do now

  1. Set up MFA on your own login. It takes a few minutes and you'll need your phone.

  2. Save your backup codes. These are your way back in if you lose your phone. Don't skip this step.

  3. If you manage your team's logins, check where everyone's up to. You can see every user's MFA status at a glance in Settings > User management, and you can help anyone who gets stuck.

Where to go next

  • [LINK: Set up multi-factor authentication]

  • [LINK: Save and use your backup codes]

  • [LINK: Manage your team's MFA]

  • [LINK: Can't sign in? Lost phone or authenticator]

  • How to set up and use passkeys — a faster way to sign in day to day

Did this answer your question?