Skip to main content

Manage your team's login & MFA

Check your team's MFA status, help users who are locked out, and get everyone ready before your region's enforcement date.

Written by Kevin Soo

If you can access account Settings, you can see where your team is up to with multi-factor authentication (MFA) and help anyone who gets stuck. You don't need to contact support.

MFA becomes required for every user on 1 September in New Zealand, 8 September in Australia, and 15 September in the United Kingdom and all other countries.

Check where your team is up to

  1. Go to Settings > User management.

  2. Look at the MFA column. It shows App for users who have set up an authenticator, and None for users who haven't.

  3. To see just the people who still need to act, filter the list by MFA device. You can also filter by state and by activity, so you can tell the difference between an active staff member who hasn't set up MFA and a login nobody has used in months.

Anyone showing None will be prompted to set up MFA the next time they sign in after your country's date, and won't be able to skip it.

What to do before your country's date

  1. Set up MFA on your own login first. You need it in place before you can help anyone else.

  2. Make sure a second person can access Settings. If you're the only admin and you lose your phone, restoring your access takes an identity check and a phone callback. A second admin removes that risk entirely.

  3. Tidy up the list while you're there. Filter by activity and remove or disable any logins nobody is using — old staff, former owners, one-off contractors. Fewer logins is less to chase and less to protect.

  4. Give your team a heads-up. Let them know it's coming, that it takes about five minutes, and that they'll need their phone. Point them at [LINK: Set up multi-factor authentication].

  5. Check the list again a week out. Chase anyone still showing None — it's much easier than sorting it out mid-shift on the day.

Remind your team to save their backup codes. Codes are shown once, at setup. A user who saves them can get themselves back in without needing you.

Reset a user's MFA (authenticator)

If someone on your team has lost their phone or can't get a working code, you can reset their MFA for them.

  1. Go to Settings > User management.

  2. Find the user on the list, and click on the down arrow to reveal more options.

  3. Choose Send authenticator reset.

Preno emails the user a link to set up their authenticator again. They complete it themselves — you don't need their phone, and you never see their codes.

Check who you're talking to. A reset request that arrives by text or email from an unfamiliar number or address is a common way attackers get into accounts. If the request feels off, verify it in person or on a number you already have for that person before you reset anything.

Reset a user's password

The same area lets you send a user a password reset. Preno emails them a link to set a new one — you don't set it for them, and you don't need to know it.

Who can do this

Managing other users — including resetting their MFA and passwords — is controlled by the "Can access the account Settings page" permission. Only give this to people you'd trust with full control of your property's account. See How to manage a user's permissions.

When someone leaves

Remove or disable their login rather than leaving it in place. MFA protects an account from outsiders; it doesn't help if a former staff member still has a working login. See How to add, remove or disable a user in Preno.

Related articles

Did this answer your question?