What is Two-Factor Authentication?
Two-Factor Authentication (2FA) adds an extra layer of security to your Bright account by requiring a verification code in addition to your email address and password each time you log in. 2FA is mandatory across all Bright products.
| Important: 2FA cannot be disabled. You can only change the method used. This guide covers both BrightHub and BrightPay (Cloud) — the setup and reset processes differ between products. |
| BrightHub — 2FA Setup & Management |
The following steps apply to BrightHub and other Bright products that use your BrightHub profile (such as BrightManager, BrightBooks, BrightAP, BrightTax and BrightPropose).
Logging In with 2FA Enabled
When 2FA is active on your account, you will see an extra verification step at login.
Step 1 — Log in to BrightHub
Enter your usual email address and password as normal.
Step 2 — Verify Your Login
You will be asked to verify your login. A one-time code will be sent using your configured 2FA method.
Step 3 — Check Your Email (or App)
Retrieve the verification code from your email inbox or authenticator app.
Step 4 — Enter the Code
Return to BrightHub, enter the code in the verification field, and click Verify.
Changing Your 2FA Method (BrightHub)
You can update your 2FA method at any time from your BrightHub profile.
1. Log in to BrightHub.
2. Click your profile icon (your initials) in the top-right corner.
3. Go to Profile → Security.
4. Update your Two-Factor Authentication method and save.
| Note: Disabling 2FA will not be possible. You can only change the method — not turn it off. |
Available 2FA Methods
The table below summarises the available methods and their relative security levels.
| Method | Security Level | What This Means |
| Authenticator App Recommended | Most Secure | Highest level of account protection |
| Moderately Secure | Simple and reliable for most users | |
| SMS | Less Secure | Convenient, but not recommended where alternatives are available |
Option 1: Authenticator App (Most Secure — Recommended)
Authenticator apps generate a time-based code on your device. We strongly recommend the Microsoft Authenticator app. Google Authenticator and Authy also work with any standard TOTP app.
How to Set It Up:
1. Go to Security Settings.
2. Select Enable Two-Factor Authentication.
3. Choose Authenticator App.
4. Download Microsoft Authenticator from the Google Play Store or Apple App Store.
5. Scan the QR code displayed on screen.
6. Enter the 6-digit code shown in the app to confirm setup.
7. Save your backup/recovery codes in a safe place.
Option 2: Email Authentication (Moderately Secure)
A one-time code is sent to your registered email address each time you sign in.
How to Set It Up:
1. Go to Security Settings.
2. Select Enable Two-Factor Authentication.
3. Choose Email and confirm your email address.
4. Enter the verification code sent to your inbox to complete setup.
Option 3: SMS Authentication (Less Secure)
A verification code is sent to your mobile phone by text message.
How to Set It Up:
1. Open Security Settings.
2. Select Enable Two-Factor Authentication.
3. Choose SMS and enter your mobile phone number.
4. Enter the code sent via text message to confirm.
Common Questions
"Why can't I turn off 2FA?"
Bright has enabled mandatory 2FA to protect your financial and client data. It cannot be disabled by you or by Support.
"Can Support turn 2FA off for my organisation?"
No. Mandatory 2FA is a security feature and cannot be disabled. Support can help you choose the simplest method for your team.
"I can't access my email or phone — how do I log in?"
Your account admin or organisation owner can reset your 2FA method from within BrightHub.
Admin Steps to Reset a Staff Member's 2FA:
1. Log in to BrightHub.
2. Select Members from the left-hand navigation.
3. Click the Manage button next to the staff member.
4. Select Reset 2FA from the dropdown.
5. Select the new authentication method.
If you select Email: The staff member will be sent a code by email on next login.
If you select SMS: You will be asked to enter and verify a mobile number. The staff member will then receive SMS codes on login.
| Admin note: If you are the admin and need your own 2FA reset, you must contact Bright Support directly: brighthubsupport@brightsg.com |
| BrightPay (Cloud) — 2FA Setup & Management |
BrightPay (Cloud) uses your Bright ID for authentication — this is separate from BrightHub. The setup, management, and reset processes are different. Follow the steps in this section if you are a BrightPay (Cloud) user.
| How it works: If you already use other Bright products with 2FA enabled, BrightPay will use the method set on your Bright ID. If no method is configured, a code will be sent by email by default. |
Setting Up or Changing 2FA on Your Bright ID
All BrightPay (Cloud) users must have 2FA enabled on their Bright ID. You can set up or change your method at any time.
1. Log in to BrightPay (Cloud).
2. Select the profile icon in the top-right corner.
3. Choose Manage My Bright ID.
4. Go to the Security tab.
5. Select 2FA Settings (shown next to the recommendation prompt).
6. Choose your preferred method: Authentication App, Text Message (SMS), or Email.
Completing setup by method:
• Authentication App or Email — select your choice and click Save.
• Text Message — enter your phone number and click Continue. Enter the verification code sent to your phone to confirm.
| Note: You can change your 2FA method at any time, but 2FA must remain enabled — it cannot be turned off. |
Enforcing 2FA at Organisation Level
Owners and Administrators can require all team members on an organisation to complete 2FA when logging into BrightPay (Cloud). This is in addition to the mandatory 2FA on each user's Bright ID.
How to enable Organisation-level 2FA:
1. Log in to BrightPay (Cloud).
2. Go to My Organisations.
3. Select your Organisation.
4. Go to Team Members.
5. Locate the 2FA/MFA settings for the Organisation.
6. Select Require Two-Factor Authentication for Organisation Members and Save.
| Who can do this? Only Owner and Administrator team member roles can enable or enforce 2FA at Organisation level. |
Common Questions
"Can certain team members be exempt from 2FA?"
No. 2FA is mandatory at Bright ID level for all users accessing BrightPay (Cloud). If you need flexibility, do not enforce 2FA at Organisation level — instead, allow each user to configure their own preferred method on their Bright ID.
"Can 2FA be turned off for individual users?"
No. Users can change their 2FA method (app, SMS, or email), but they cannot disable 2FA entirely.
I'm Locked Out — How Do I Reset My 2FA? (BrightPay)
If you still have access to your account, you can change your 2FA method yourself via your Bright ID profile (see steps above). If you are locked out and cannot access your 2FA method, follow the process below.
Step 1 — Email BrightPay Support
Contact the support team at: brightpaysupport@brightsg.com
Step 2 — Provide GDPR Authorisation
For data protection purposes, the request must be authorised by the appropriate person depending on your account type. Refer to the table below.
| Account Type | Who Must Authorise the Reset |
| Employee | Your payroll processor or manager must email Support to confirm the request. |
| Manager | Your payroll processor must email Support to confirm the request. |
| User (Client Portal) | Your payroll processor must email Support to confirm the request. |
| Team Member (Admin / Payroll Processor) | Another Admin on the account must email Support to confirm. If no other Admin or Owner exists, an email from the CEO or Business Owner is required. |
Step 3 — Support Resets Your Method
Once authorisation is confirmed, Support will switch your 2FA to a method you can access (for example, back to email). 2FA will remain enabled — only the method is changed. You can then log in and set up your preferred method again.
| Urgent? If you need access immediately (e.g. to run payroll), call BrightPay Support so your case can be prioritised. |
I've Lost My Phone Number — How Do I Regain Access?
If you can no longer access the phone number registered for SMS-based 2FA, you will not be able to remove or bypass 2FA without contacting Support.
Contact Support at: brightpaysupport@brightsg.com (or by phone for urgent cases).
To verify your identity, you may be asked to provide:
• The account email address
• Your company name
• Billing details (e.g. last 4 digits of card, recent invoice number, or other agreed details)
Once your identity is confirmed, Support will update your 2FA so you can log in and configure a new phone number or alternative method.
Our Recommendation
Across all Bright products, for the best balance of security and convenience:
• Authenticator App — Offers the strongest protection and is our preferred option for all users.
• Email — A reliable alternative if you do not have access to a mobile device.
• SMS — Available where needed, but not recommended as a long-term method.
Need Help?
For BrightHub or other Bright products (BrightManager, BrightAP, BrightTax BrightBooks, BrightPropose):
• Your account admin can reset your 2FA from within BrightHub via Members → Manage → Reset 2FA.
• Use the in-product AI-powered support tool for guided assistance.
• If you are the admin and need your own 2FA reset, contact Bright Support directly brighthubsupport@brightsg.com
For BrightPay (Cloud):
• Email brightpaysupport@brightsg.com with the required authorisation (see Lockout section above).
• For urgent cases, call BrightPay Support to have your case prioritised.