> For the complete documentation index, see [llms.txt](https://enterprise-ipi-en.hideez.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://enterprise-ipi-en.hideez.com/ipi-enterprise-server/single-sign-on-settings/user-settings.md).

# User settings

IPI Enterprise Server – User settings

When administator [added your account](/ipi-enterprise-server/employees/how-to-add-an-employee.md) and [enabled SSO option](/ipi-enterprise-server/single-sign-on-settings/nastroika-polzovatelei.md), you have to open the link in the email from the server (delivered after user SSO enabling, described in previous section) and register your user.

## Two-factor authentication required

You will see the next screen. Click the "**Next**" button. Also here you can change the display language.

<figure><img src="https://2664185294-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FABkYqOD4zp314dETCDQJ%2Fuploads%2Fgit-blob-214c209cec4692f74fa2b7e54a30d40c423299f7%2Fimage%20(235).png?alt=media" alt="" width="375"><figcaption></figcaption></figure>

If your administrator [enabled second-factor authentication](/ipi-enterprise-server/single-sign-on-settings/nastroika-polzovatelei.md) you have to set and confirm password.

<figure><img src="https://2664185294-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FABkYqOD4zp314dETCDQJ%2Fuploads%2Fgit-blob-b1a352dcb03c80adee77209308787510ada76994%2Fimage%20(494).png?alt=media" alt="" width="375"><figcaption></figcaption></figure>

Then you have to set up the second factor:

<figure><img src="https://2664185294-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FABkYqOD4zp314dETCDQJ%2Fuploads%2Fgit-blob-295b10eb6199ba59dcf596aca48e814af8e29c4c%2Fimage%20(43).png?alt=media" alt=""><figcaption></figcaption></figure>

### 1. Passkey<br>

* If you have a hardware security key (for example, **IPI Key**) or your smartphone as a Passkey, choose the "Cross-Platform" option.
* If you want to use a platform key (such as a biometric sensor or PIN code from your computer/smartphone), choose the "Platform" option. Then follow the instructions on the screen.<br>

<figure><img src="https://2664185294-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FABkYqOD4zp314dETCDQJ%2Fuploads%2Fgit-blob-032c313aad46351db117107f8643f40cb34a1a55%2Fimage%20(412).png?alt=media" alt="" width="375"><figcaption></figcaption></figure>

### 2. IPI Authenticator

<figure><img src="https://2664185294-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FABkYqOD4zp314dETCDQJ%2Fuploads%2Fgit-blob-7976744b2a097fc6412de71dd1d381297952925b%2Fimage%20(623).png?alt=media" alt="" width="375"><figcaption></figcaption></figure>

### 3. OTP Authenticator App<br>

After successfully enabling two-factor authentication, you will be prompted to save your recovery codes. 10 codes, each of which consists of 8 characters. You can log in with their help if for some reason you cannot enter the OTP code.

<figure><img src="https://2664185294-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FABkYqOD4zp314dETCDQJ%2Fuploads%2Fgit-blob-756b779d131510a152cdf5e73bbf48aec4737f31%2Fimage%20(217).png?alt=media" alt="" width="375"><figcaption></figcaption></figure>

​[Log in with the recovery code.​](/ipi-enterprise-server/administration/how-to-enable-two-factor-authentication-at-ipi-enterprise-server.md#log-in-with-recovery-code)

After successful sign in you can configure all these login options, change password, see the list of registered security keys in the "**FIDO2 Authenticators"** section (cross-platform and platform separately) and enroll new device (for example, smartphone) for single sign on, change page language, etc. Just choose desired setting and follow the instructions on the screen.

![](https://2664185294-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FABkYqOD4zp314dETCDQJ%2Fuploads%2Fgit-blob-f4e8caebf2a32a84a329c0426188afbf81fa2856%2Fimage%20\(498\).png?alt=media)

### Second factor is not required

If two-factor authentication is not required you have to set up sign in option. Also here you can change the display language.

<figure><img src="https://2664185294-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FABkYqOD4zp314dETCDQJ%2Fuploads%2Fgit-blob-f65c1d264a0e8b29dfb0d71ce9675cce337e3373%2Fimage%20(223).png?alt=media" alt="" width="375"><figcaption></figcaption></figure>

1. Use FIDO2 Authenticator<br>

   <figure><img src="https://2664185294-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FABkYqOD4zp314dETCDQJ%2Fuploads%2Fgit-blob-e853d53d4a4896a2647d53335d25778807099585%2Fimage%20(520).png?alt=media" alt=""><figcaption></figcaption></figure>

   \- If you have a hardware security key (for example, IPI Key), choose the "Cross-Platform" option.\
   \- If you want to use a platform key (such as a biometric sensor or pin code from your computer/smartphone), choose the "Platform" option.\
   \
   In this case you can choose "use usernameless" option that allows you to login without username.\
   \
   Then follow instructions on the screen.<br>
2. Use IPI Authenticator\
   \
   Follow instructions on the screen.\
   \
   ![](https://2664185294-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FABkYqOD4zp314dETCDQJ%2Fuploads%2Fgit-blob-7976744b2a097fc6412de71dd1d381297952925b%2Fimage%20\(623\).png?alt=media)<br>

After successful sign in you can configure all these login options, see the list of registered security keys in the "**FIDO2 Authenticators"** section (cross-platform and platform separately) and enroll new device (for example, smartphone) for single sign on, change page language, etc. Just choose desired setting and follow the instructions on the screen.

![](https://2664185294-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FABkYqOD4zp314dETCDQJ%2Fuploads%2Fgit-blob-3f232ae58ea91a6b21dab4936ff45f0a2669ed5f%2Fimage%20\(687\).png?alt=media)

### Disabling 2FA at IES <a href="#disabling-2fa-at-hes" id="disabling-2fa-at-hes"></a>

To disable two-factor authentication on the IES server, go to the **One-Time Password** section and click **Disable 2FA**.

![](https://2664185294-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FABkYqOD4zp314dETCDQJ%2Fuploads%2Fgit-blob-a0e2c8135788a836448c0b7eac7366fab73b6511%2F2fa%20on%20hes3.jpg?alt=media)

Confirm the action.

![](https://2664185294-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FABkYqOD4zp314dETCDQJ%2Fuploads%2Fgit-blob-870e3eab291f1d88666c6c14f7d0ca0cdbe7898d%2Fimage%20\(501\).png?alt=media)

Two-factor authentication is disabled. But you can always resume it.

### How to enable 2FA again

Go to the **One-Time Password** and click on the **Add OTP app** button. Then follow the instructions on screen.

<figure><img src="https://2664185294-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FABkYqOD4zp314dETCDQJ%2Fuploads%2Fgit-blob-20259ac564920eede65808dcc8dd42b0525e07b2%2Fimage%20(319).png?alt=media" alt=""><figcaption></figcaption></figure>

### Resetting recovery codes at IES

After you [disable 2FA](#disabling-2fa-at-hes) on IES and [enable it](#undefined) again, your recovery codes will be reset.

Please, note, if you just reset the OTP application, recovery codes will be not reset.
