Two-factor authentication: the email sign-in code
Current asks for a second factor on every password sign-in. There is no per-person setting and no workspace switch that turns it off: sign in with an email address and a password and you finish with a second step. Out of the box that step is a 6-digit code emailed to the address on your account. You can replace it with an authenticator app or a passkey, and your workspace can require one. If your workspace signs in through single sign-on, none of this reaches you — your identity provider is the second factor.
Forgot the password itself? On the sign-in page, enter your email, choose the password step, and click "Forgot password?" Enter your email and we send you a 6-digit reset code (check spam). Type that code on the same screen, choose a new password, and you are done — then sign in with the new password. There is no link to click, so it still works when the email opens on your phone and you are at your desk. The code expires in 15 minutes and can only be used once.
Resetting your password does not skip the second factor, and it does not sign you in by itself. Those are two different checks: the reset code proves you can reach your mailbox, and the second factor proves the sign-in is yours. Someone who gets into your email still cannot get into Current. Resetting also signs out anything already signed in as you and un-trusts your devices, so if someone else knew your old password, changing it actually removes them.
Current carries real PSA billing data, partner project data, and your entire CRM. A leaked or reused password shouldn't be enough to get someone into Current, and the second factor means it isn't.
What happens when you sign in
- 1Sign in with your email and passwordCurrent checks whether this browser already holds a valid trusted-device token for you. If it does, you go straight to the app and never see a second step.
- 2Finish the second stepWith no trusted device, Current asks for your factor. On the default setting that is a code: you land on a "Check your email" screen and one is sent immediately, from Current's notifications address with the subject "Your Current sign-in code" followed by the code itself, so it is easy to spot and easy to find in a spam folder. If you have added an authenticator app or a passkey, Current asks for that instead and sends no email at all.
- 3Enter the 6 digitsType the code and choose Verify & sign in. The code is single-use: verifying it consumes it, so it can't be replayed.
- 4Your browser is trusted for a whileA verified factor issues a trusted-device token that lives in that browser for 30 days, or for the shorter window your workspace has chosen. You won't be challenged again on that browser until it expires — or until you switch browsers, switch machines, use a private window, or clear your site data.
Authenticator apps and passkeys
Settings → Sign-in security is where you add an authenticator app (Microsoft Authenticator, Google Authenticator, 1Password, any TOTP app) or a passkey (Face ID, Touch ID, Windows Hello, a security key). Once you have either, Current stops offering you the emailed code and asks for the app or the passkey instead, which also means a mail outage can no longer hold up your sign-in. Removing a factor asks you to use it first. The walkthrough is "Authenticator apps and passkeys".
The limits, exactly
The code path is rate-limited on both sides — how fast codes can be requested, and how many times a wrong one can be guessed. Both limits are counted per person on the server, so they survive requesting a fresh code.
| Rule | Value | What you'll see |
|---|---|---|
| Code lifetime | 10 minutes | "That code expired — request a new one." |
| Resend cooldown | 20 seconds | Pressing Resend code inside 20 seconds keeps the existing code alive instead of sending a second one. |
| Codes you can request | 10 per hour | Past that, the account locks for about 15 minutes — the anti mail-bomb cap. |
| Wrong codes in a row | 5 | The fifth wrong code locks the account for about 15 minutes and clears the pending code. A wrong recovery code counts against the same five. |
| Trusted device | 30 days by default | No challenge on that browser until it expires. A workspace can shorten the window to 14 or 7 days. |
What your workspace can require
A Tenant Admin runs all of this from one place: the Sign-in panel at Workspace → Users & roles. It lists the three ways in, strongest first (single sign-on, an authenticator app or passkey, the emailed code), with each one's current state and its single action; the trusted-device window; and a roster of who signs in how, with the trusted-device count and last sign-in per person and a Reset second factor action beside anyone on a password. The two controls only move in the tightening direction, and every change is written to the audit log.
- +Second factor for password sign-ins — Email code, which is the default, or Authenticator app or passkey. Raising it cannot be undone. After it, the emailed code is no longer offered to anyone on a password: people who already have an app or a passkey carry on unchanged, and anyone without one is asked to set one up at their next sign-in, before they reach the workspace.
- +Trusted device window — 30, 14 or 7 days. It only ever gets shorter, and shortening it trims the devices that are already trusted, so a browser trusted 28 days ago on a workspace that has just chosen 7 days is challenged on its next visit.
- +There is no third control that turns the second factor off, for anyone, including a Tenant Admin.
When something goes wrong
- +No code arrived — wait 20 seconds, choose Resend code, and check spam and quarantine. The subject line contains the code itself, so a search for "Current sign-in code" usually finds it.
- +"Too many attempts — try again in about 15 minutes" — that's the lockout. It clears on its own; there is no admin override to shortcut it. Wait it out rather than hammering Resend code, which counts against the hourly cap.
- +"No email address is on file for this account" — your account was created without an email address. A Tenant Admin has to add one before you can sign in; see "Invite team members and assign roles".
- +"Two-factor email isn't set up for this workspace yet" — the workspace's email sending isn't finished. Sign-in is refused on purpose rather than waved through. Your admin should complete email setup; see "How Current sends email — and why two mail paths, not one".
- +A screen saying your workspace signs in with single sign-on — your email domain is on an SSO-enforced workspace, so the password path stops there. Sign in with the button on that page. A Tenant Admin who cannot reach the identity provider can use a recovery code from the same screen; see "If your identity provider is down: recovery codes and password windows".
- +Asked for an authenticator app you never set up — your workspace has raised its floor. Follow the enrolment prompt; it takes you through adding an app or a passkey and then signs you in.
- +Challenged on every sign-in — the trusted-device token lives in your browser's local storage. Private windows, aggressive privacy extensions, or a policy that clears site data on exit will drop it every time, so every sign-in asks again. That's working as designed.
- +Stuck on the code screen — there is always a Sign out link on that page. Signing out and starting again is safe.
For admins
- +There is no per-person 2FA toggle to switch on and no workspace switch to turn it off. Every password session is covered, including the partner portal — a partner signing in with a password gets the same second step.
- +Single sign-on is the setup we recommend. MFA, conditional access and offboarding all follow your identity provider, nobody types a code, and disabling a person in one place ends their access to Current. See "Set up single sign-on (Microsoft Entra ID, Okta, Google Workspace)".
- +If somebody loses the phone their authenticator app lived on, open the ⋯ menu on their row at Workspace → Users & roles and choose Reset second factor. It clears their factors and un-trusts every browser they had, so their next sign-in starts over: the emailed code, unless your workspace requires an app, in which case they enrol a new one first. ITPartners+ support can run the same reset when no admin can get in.
- +Offboarding is still the real control. Deactivating someone in Workspace → Users & roles cuts their data access at the database, whatever trusted device or factor they still hold, and drops them on an "access turned off" screen on their next page load.
- +If a laptop is lost, deactivate the person (or move the workspace to single sign-on and let the provider handle revocation). A trusted-device token is bound to the account, so removing the account's access removes the token's value.
