Hello, I’m Nora, your AI guide from Technology Last Stop. This guide covers Set up your company authenticator and recover access. A separate authenticator flow enforces a second factor for company owners, administrators, billing users and regular clients. Existing TLS staff Verify registrations remain separate. Current availability: Implemented; real customer enrollment acceptance required. Before you start. An approved company account, a fresh primary sign-in and an authenticator app. A protected TLS encryption key. Never send an authenticator key, current code or recovery code in a ticket. Step 1. Sign in with your existing approved Microsoft, Google or email account. Company accounts are directed to the authenticator page before protected portal access. Step 2. Choose Set up authenticator. Scan the QR code from your authenticator app, or expand Enter the key manually. The QR is created locally in your browser; no external QR service receives the key. Step 3. Enter the current six-digit code. First-time setup expires after ten minutes and belongs to the browser session that started it. Step 4. Save the eight recovery codes shown after successful enrollment. Each works once. Store them securely, separately from your phone, and select I have saved my recovery codes securely. Step 5. Continue to the workspace. On later sign-ins, enter a current authenticator code or one unused recovery code. A code already used by another sign-in cannot be replayed. Step 6. For a lost phone and no remaining recovery code, contact TLS. A verified TLS owner opens Companies > Users > Recovery and sessions > Recover company authenticator, completes identity review and records the recovery case. Step 7. After recovery, all of that user’s sessions and recovery codes are revoked. The user signs in again and enrolls a new authenticator. This does not reset a TLS staff Verify device. Now verify the result. A company owner, billing administrator and ordinary client cannot read protected company APIs before MFA. Complete enrollment with a real authenticator on each supported browser; confirm recovery codes work exactly once. A second company cannot reset, inspect or verify the first company’s authenticator. If you get stuck. Too many attempts: wait 15 minutes. Starting setup again cannot clear the account’s attempt limit. Code mismatch: use automatic time on the phone and wait for a new code. Setup expired or used another tab: start again from a fresh sign-in; setup secrets are never returned from the status endpoint. Recovery requires an identity-verified TLS owner. Primary sign-in alone cannot overwrite an existing authenticator. Use the current written guide for exact URLs, permission names, and provider documentation. Pause before entering credentials, and keep them in protected configuration. I’m Nora, your TLS guide.