Two-Factor Authentication (2FA) adds an additional security step to your AIUNIFY PROS SUITE account.
When 2FA is enabled, signing in requires:
Email + Password
and then:
Authenticator Code or Recovery Code
The current PROS SUITE security interface uses TOTP-based Two-Factor Authentication, which works with authenticator applications that generate rotating security codes. When enabled, the Security panel states:
“Two-Factor Authentication is Enabled”
and:
“Your account is secured with 2FA TOTP.”
This chapter covers:
Two-Factor Authentication is managed through the PROS SUITE Settings interface.
Open:
User Menu → Settings
The Settings dialog contains two primary sections:
The Settings interface describes its purpose as:
“Manage your API keys and security settings.”
Select:
Security (2FA)
to open the Two-Factor Authentication controls.
To open the 2FA controls:
The Security tab loads the dedicated Two-Factor setup interface.
When Security opens, PROS SUITE checks whether 2FA is currently active for the account.
You will generally see one of two primary states.
The panel displays:
Two-Factor Authentication is Disabled
with:
“Add an extra layer of security to your account by requiring a security code when logging in.”
and a:
Set Up 2FA
button.
The panel displays:
Two-Factor Authentication is Enabled
and:
“Your account is secured with 2FA TOTP.”
PROS SUITE identifies its current 2FA method as TOTP.
TOTP stands for Time-Based One-Time Password.
An authenticator application generates a temporary numeric code based on the security configuration established between your account and the authenticator application.
In PROS SUITE, the normal Sign In verification code contains:
6 digits.
The code changes periodically in your authenticator application.
During setup, PROS SUITE specifically tells the user to scan the QR code with an authenticator application and gives examples including:
You are not limited to one of those examples as long as the authenticator application supports the required TOTP setup.
Before beginning setup, have the following available:
It is especially important to plan where you will securely store your Recovery Codes before completing setup.
PROS SUITE explicitly warns that Recovery Codes are used if you lose access to your authenticator application.
When the Security panel says:
Two-Factor Authentication is Disabled
select:
Set Up 2FA.
PROS SUITE then starts the 2FA setup process and prepares:
The user is moved into:
Set Up Authenticator App.
The setup screen contains two ways to add PROS SUITE to your authenticator:
Use the authenticator application's QR-code scanner.
Use the Secret Key displayed beneath the setup instructions.
Both methods configure the authenticator for the same PROS SUITE 2FA setup.
The recommended setup sequence displayed by PROS SUITE begins with:
“Scan this QR code using your authenticator app.”
To use the QR code:
Do not close the PROS SUITE setup screen yet.
You must verify the setup before 2FA becomes active.
If your device cannot scan the QR code, PROS SUITE provides an alternative.
The setup interface states:
“If you can't scan the code, enter this secret key manually in your app.”
To use it:
Treat the displayed 2FA Secret Key as sensitive security information.
Anyone who possesses that key may potentially be able to configure a compatible authenticator that generates codes for the same 2FA configuration.
As a security practice:
The Secret Key exists to establish the authenticator connection, not as ordinary account information.
Adding PROS SUITE to an authenticator application does not by itself complete 2FA activation.
The setup screen includes:
Verify the Setup
with the instruction:
“Enter the 6-digit verification code generated by your authenticator app to complete the setup.”
This verification confirms that the authenticator has been configured correctly.
After adding PROS SUITE to your authenticator:
Confirm & Enable
The button is not enabled until six digits have been entered.
If fewer than six digits are provided and verification is attempted, PROS SUITE can report:
Please enter the 6-digit confirmation code.
Return to your authenticator application and enter the complete current code.
If the setup code cannot be verified, PROS SUITE does not enable 2FA.
The entered code is cleared so another code can be provided.
If this happens:
When verification succeeds, PROS SUITE:
2FA has been successfully enabled!
At this point, your next Sign In can require the second authentication factor.
Immediately after successfully enabling 2FA, PROS SUITE displays:
Save Your Recovery Codes.
This step should not be skipped.
The interface explains:
“If you lose access to your authenticator app, you can use these recovery codes to log in.”
It also states:
“Each code can only be used once.”
Recovery Codes are your backup authentication method.
They are useful when you cannot obtain a normal six-digit authenticator code because, for example:
At Sign In, PROS SUITE provides:
Use a recovery code instead.
The PROS SUITE Recovery Code screen explicitly states:
Each code can only be used once.
Therefore:
Unused Recovery Code → Available
Used Recovery Code → Do not rely on it again
Keep track of your remaining unused Recovery Codes.
During Sign In recovery, PROS SUITE describes the expected Recovery Code format as:
XXXX-XXXX
and refers to it as an 8-character recovery code.
These codes are different from the standard six-digit authenticator codes.
PROS SUITE recommends storing the Recovery Codes in a secure location such as a password manager.
The interface provides two convenient controls:
Select:
Copy Codes
to copy the complete Recovery Code collection to the clipboard.
PROS SUITE confirms:
Recovery codes copied to clipboard.
Immediately store the copied values somewhere appropriately secured.
Do not leave them indefinitely in an unsecured clipboard manager, message, or plain note.
Select:
Download .txt
to download a text file containing the Recovery Codes.
The current filename is:
2fa_recovery_codes.txt.
After downloading it, store the file securely.
The downloaded Recovery Code file can be used as part of your account's second-factor recovery process.
Do not store it somewhere that unauthorized users can freely access.
Consider protecting it using:
Do not attach it to ordinary Email messages or upload it to publicly accessible storage.
After securely saving the Recovery Codes, select:
I've Saved the Codes.
PROS SUITE then returns to the normal 2FA status view and rechecks the account's current 2FA status.
After setup, return to:
Settings → Security (2FA)
The panel should display:
Two-Factor Authentication is Enabled
and:
Your account is secured with 2FA TOTP.
This confirms that PROS SUITE recognizes the account as 2FA-enabled.
After enabling 2FA, a normal future Login becomes:
Email Address
↓
Password
↓
Log in
↓
Two-Factor Authentication
↓
6-Digit Authenticator Code
↓
Dashboard
The Login system specifically detects accounts requiring 2FA and moves them into a dedicated verification state rather than completing the Sign In immediately.
When required during Login, the Two-Factor screen instructs:
“Open your authenticator app and enter the 6-digit security code.”
Enter the complete six-digit code.
PROS SUITE automatically submits the normal authenticator code when all six digits have been entered.
The current Login verification screen provides a five-minute verification session.
It displays:
Code expires in [time].
If the session expires:
Verification session expired. Please log in again.
This means you must restart the Login process.
If your authenticator application is unavailable:
Use a recovery code instead
Two-Factor Recovery
Verify Recovery Code
If you switch to Recovery Code mode and then regain access to your authenticator application, select:
Use authenticator app instead.
You can then enter the normal six-digit authenticator code.
Because Recovery Codes are single-use, you may eventually want a new set.
PROS SUITE provides:
Regenerate Recovery Codes
from the enabled 2FA panel.
This does not require disabling 2FA.
Navigate to:
Settings → Security (2FA)
When 2FA is enabled:
The regeneration workflow requires your account Password.
Before generating new codes, PROS SUITE states:
“Regenerating recovery codes will invalidate your current ones. Enter your password to continue.”
This is critical.
Once regeneration succeeds:
Old Recovery Codes → Invalid
New Recovery Codes → Active
Do not continue relying on an older saved copy.
To regenerate Recovery Codes, enter your account Password into:
Password
with the placeholder:
Confirm account password.
If no Password is supplied, PROS SUITE reports:
Account password is required.
After entering your Password, select:
Regenerate Codes.
If successful, PROS SUITE:
New recovery codes generated successfully!
After regeneration:
Because regeneration invalidates the previous codes, keeping only an obsolete copy could leave you without a usable recovery method.
If you open the regeneration panel but do not want to continue, select:
Cancel.
The confirmation form closes and its Password value is cleared.
When 2FA is active, the Security panel also contains:
Disable 2FA.
Disabling 2FA removes the additional authentication requirement from future Sign Ins.
Because this reduces account security, PROS SUITE requires additional identity verification before allowing it.
After selecting Disable 2FA, PROS SUITE displays:
Confirm Disabling 2FA
with:
“Disabling two-factor authentication makes your account less secure. You must verify your identity to perform this action.”
Review this warning before continuing.
The Disable 2FA form requires two pieces of information:
Your current PROS SUITE account Password.
The field accepts:
6-digit code or recovery code.
Both fields are required.
To disable Two-Factor Authentication:
If either required value is missing, PROS SUITE displays:
Both password and verification code are required.
Enter both values before trying again.
When the request succeeds, PROS SUITE:
2FA has been disabled.
The Security panel will then return to:
Two-Factor Authentication is Disabled.
If you decide not to disable 2FA:
Select:
Cancel
The confirmation panel closes and the entered Password and Verification Code are cleared.
No 2FA change is made.
For most users, leaving 2FA enabled provides stronger account protection.
This is especially valuable when the account provides access to:
A compromised Password alone is less useful to an attacker when a second authentication factor is also required.
You usually do not need to disable 2FA simply because:
Instead use:
Regenerate Recovery Codes
This keeps Two-Factor Authentication active while replacing the backup codes.
The current user-facing source does not expose a separate Move Authenticator or Replace Authenticator Device workflow.
Therefore, this manual should not invent one.
If you need to replace the authenticator configuration and the current interface does not provide a direct transfer function, use the available account-security controls and follow your organization's approved security procedure.
Do not delete your existing authenticator entry until you know you still have a working method to access the account.
Once setup has completed and 2FA is enabled, the normal enabled panel exposes:
The current user-facing source does not establish a button that simply re-displays the existing QR code or Secret Key.
Therefore, save the appropriate recovery information during initial setup rather than assuming the setup QR code will always remain available.
These two code types are different.
| CodePurposeFormat | ||
| Authenticator Code | Normal second-factor Sign In | 6 digits |
| Recovery Code | Backup when authenticator is unavailable | XXXX-XXXX |
| Password Reset OTP | Password Recovery only | 6 digits |
Do not confuse a Password-reset OTP with a Two-Factor Authenticator Code.
A Recovery Code does not replace the normal account Password.
The normal recovery-login sequence remains:
Email + Password
↓
Two-Factor Verification
↓
Recovery Code
The Recovery Code replaces the second-factor authenticator code, not the Password itself.
Even when 2FA is enabled, continue protecting your account Password.
PROS SUITE specifically requires the Password for sensitive security actions such as:
Regenerating Recovery Codes
and:
Disabling 2FA.
2FA supplements Password security rather than replacing it.
If selecting Set Up 2FA fails:
If setup cannot be initiated, PROS SUITE can display an error indicating that 2FA setup failed to start.
If your authenticator cannot scan the QR code:
Use the manual setup option.
PROS SUITE provides the Secret Key specifically for this situation.
Enter it manually in your authenticator application and then continue to Verify the Setup.
Check that:
If setup was entered incorrectly, cancel the incomplete setup and begin Set Up 2FA again.
The Confirm & Enable button remains disabled while fewer than six characters are entered into the verification field.
Enter the complete six-digit code from your authenticator app.
If the six-digit setup code is rejected:
The setup process clears an unsuccessful code so another can be entered.
If you have already enabled 2FA and cannot access the authenticator app:
Use a recovery code instead
Remember:
Each Recovery Code can only be used once.
If a Recovery Code is rejected:
If you previously selected:
Regenerate Recovery Codes
your earlier codes are no longer valid.
PROS SUITE explicitly warns:
“Regenerating recovery codes will invalidate your current ones.”
Use the newest saved Recovery Code collection.
Immediately after enabling 2FA, PROS SUITE displays the Recovery Code save screen.
If you have already left that screen and no longer possess the codes but still have normal authenticated account access, use:
Settings → Security (2FA) → Regenerate Recovery Codes
You will need your account Password.
Then securely save the newly generated set.
Password Recovery and Two-Factor Authentication are independent security processes.
If you forget the Password:
Resetting the Password does not, based on the current user-facing workflow, automatically disable Two-Factor Authentication.
If you take too long at the 2FA Sign In screen, PROS SUITE can display:
Verification session expired. Please log in again.
Select:
Back to Login
and authenticate again.
To disable 2FA, the current interface requires:
The Verification Code field accepts:
6-digit code or recovery code.
If either value is missing, the action cannot proceed.
Recovery Code regeneration requires:
Account Password
If it is missing:
Account password is required.
If you have forgotten the Password, use Password Recovery before attempting this account-security action.
For stronger protection:
A good recovery strategy should protect against both:
Unauthorized access
and:
Loss of access
For example, securely retaining Recovery Codes somewhere separate from the authenticator device can help if that device is lost.
PROS SUITE specifically recommends a secure location such as a password manager.
The initial setup screen can expose:
and the success screen exposes:
These are account-security materials.
Avoid saving screenshots of these screens in automatically synchronized photo libraries unless doing so is part of an approved secure credential-storage practice.
The complete first-time setup process is:
Sign In
↓
User Menu
↓
Settings
↓
Security (2FA)
↓
Two-Factor Authentication is Disabled
↓
Set Up 2FA
↓
Set Up Authenticator App
↓
Scan QR Code
or:
Enter Secret Key
↓
Authenticator Generates 6-Digit Code
↓
Verify the Setup
↓
Confirm & Enable
↓
2FA Successfully Enabled
↓
Save Your Recovery Codes
↓
Copy Codes / Download .txt
↓
Store Securely
↓
I've Saved the Codes
↓
Two-Factor Authentication is Enabled
After setup, future Sign Ins follow:
Email address
↓
Password
↓
Log in
↓
Two-Factor Authentication
↓
Authenticator App
↓
6-Digit Security Code
↓
Dashboard
If the authenticator is unavailable:
Use a recovery code instead
↓
Recovery Code
↓
Verify Recovery Code
↓
Dashboard
When new backup codes are needed:
Settings
↓
Security (2FA)
↓
Regenerate Recovery Codes
↓
Warning: Current Codes Will Be Invalidated
↓
Confirm Account Password
↓
Regenerate Codes
↓
Save Your Recovery Codes
↓
Copy / Download
↓
I've Saved the Codes
If 2FA must be removed:
Settings
↓
Security (2FA)
↓
Disable 2FA
↓
Confirm Disabling 2FA
↓
Account Password
↓
6-Digit Code or Recovery Code
↓
Disable 2FA
↓
2FA has been disabled
↓
Two-Factor Authentication is Disabled
After setup, verify:
Keep these four credentials separate:
Used during normal Sign In and certain security changes.
Used to establish the authenticator application's TOTP configuration.
Used as the normal second factor during Sign In.
Used as a backup second factor when the authenticator is unavailable.
These values serve different purposes and should not be substituted for one another unless the interface explicitly permits it.
The source-verified user interface does not currently establish separate controls for:
Therefore, this manual does not present those as currently available PROS SUITE user features.
The documented 2FA system is the Authenticator/TOTP + Recovery Code workflow verified in the source.
AIUNIFY PROS SUITE provides a complete TOTP Two-Factor Authentication system through:
Settings → Security (2FA).
When 2FA is disabled, the user can select:
Set Up 2FA
and configure an authenticator by either:
Scanning the QR Code
or:
Entering the Secret Key manually.
The setup is completed by entering a:
6-digit verification code
and selecting:
Confirm & Enable.
After activation, PROS SUITE generates Recovery Codes and instructs the user to save them securely. Each Recovery Code can only be used once, and the interface allows users to Copy Codes or Download .txt.
Once enabled, users can:
Regenerating codes invalidates the old set. Disabling 2FA requires both the account Password and a six-digit Verification Code or accepted Recovery Code.
The essential security workflow is:
Password + Second Factor + Secure Recovery Method
Together, these controls provide the core account-security layer for AIUNIFY PROS SUITE.