Sundial · Your SPE Portal
Two-factor authentication
A plain-language guide to the second sign-in step — what it is, when Sundial asks for it, and what to do if something goes wrong.
What it is, in one paragraph
A password is one thing you know. Two-factor authentication (2FA, or “two-step verification”) adds a second thing you have — an authenticator app on your phone, or a text message — so that a stolen or guessed password alone can’t get into your account. It’s the same idea your bank, email, and most financial apps already use.
When does Sundial actually ask for it?
You’re never stopped from signing in and looking around while you decide. Where it matters is the moment you go to open something that matters — your documents, distributions, tax facts, or the Vault — Sundial asks you to verify it’s really you first, the same way a bank app might ask you to re-confirm before a transfer. If you haven’t set up a second step yet, that’s the moment it’ll ask you to.
You can also turn it on any time from Settings, before you’re asked — recommended if you’d rather do it once, up front, and not think about it again.
Your options
- Authenticator app — recommended
- A free app on your phone (Google Authenticator, 1Password, Authy, Microsoft Authenticator, and others all work the same way) generates a fresh 6-digit code every 30 seconds. It works without a signal or Wi-Fi, and it can’t be redirected the way a text message sometimes can. Setup is one QR-code scan.
- Signing in with an email link, instead of a password
- From the sign-in page, “Prefer a sign-in link instead of a password?” emails you a one-tap link. That replaces your password, not your second factor — you’ll still be asked for a code from your authenticator app before opening anything sensitive. (If your account’s second factor were also an email code, anyone who got into your inbox would have both steps at once — so we don’t offer that particular combination.)
Troubleshooting
- “That code didn’t work,” and I typed it right
- Authenticator codes are time-based — if your phone or computer’s clock has drifted even by a minute or two, a correctly-typed code will still fail. Check that your device’s clock is set to update automatically, then try the next code (a fresh one appears every 30 seconds).
- I lost my phone or authenticator app
- Use one of the one-time recovery codes you saved when you set up two-factor — the “Use a recovery code” link on the verification page. That clears your old factor so you can set up a fresh one. No recovery codes either? An admin can reset your two-factor from the Members page; ask them.
- I didn’t get a text message
- Double check the number in Settings, and that your phone has signal. If it still doesn’t arrive, switching to an authenticator app avoids the problem entirely — it needs no signal to generate a code.
- I want to turn it off
- You can, from Settings → Two-factor authentication — but every time you go to open something sensitive (documents, distributions, the Vault), you’ll be asked to set it back up first. There’s no way around that part; it’s what actually protects that data.