How To Add 2 Factor Authentication to Protect Your Xero Account


A huge bee in everyone’s bonnet right now is IT security. And as you’re accessing your company’s financials with Xero, you’ll want to make sure your account is as secure as can be. Adding two factor authentication (or as Xero calls it, two step authentication) to your account will help you do just that.

A quick word on two-factor: While nothing can guarantee your account’s safety, two factor authentication will get you pretty close. Two-factor in security means you have to have 2 things to get access — usually something you know, and something you have. For many apps it’s something you know — a password — and something you have — an authenticator app on your mobile.

Start by logging into Xero. In the upper right hand corner you’ll see your name. Click on that.

That will bring up your account menu. Click on the Account button.

Now you’re in the account settings screen. Here you can do things like change your email, your password, etc. About halfway down the page, you’ll see a section labeled Two-step authentication. If you have not already set up two factor authentication, you’ll have a green setup button. Click on that.

The next screen will show you some instructions and a QR code. That QR code is what you’ll scan with the app on your phone or tablet. Now it’s time to switch to your mobile device.

Another quick note: The Xero instructions have a link to the Google Authenticator app, but you can also use the Windows Authenticator app, even on an Android or iPhone. Our screenshots are from the Google app.

On your mobile device, open your authenticator app. If you don’t have one already, you can download either the Google Authenticator app or the Windows Authenticator app from the iTunes or Google Play store. Our screenshots will be from the Google app.

To add Xero authentication, click on the big red circle with the plus in it.

A menu will appear at the bottom of the screen. Select Scan a barcode.

The app will bring up your mobile’s camera with a target-like center. Focus that on the QR code on your computer screen.

Once your mobile device has captured the code, the main page of the app will reload, this time with your authentication security code for Xero displayed. This code will change every 60 seconds.

Now back to your computer — click Next on the QR code screen in Xero.

Xero will now want you to authenticate with the number showing in your mobile app. The Next button will be disabled until you have typed in the box.

After you’ve entered the number into Xero that is displayed in your authenticator app on your mobile device, the Next button becomes active. You can now click Next.

Almost done.

The last step is to set up some security questions in Xero. These questions will make it so you can still get into your account even if you can’t get to your authenticator app in the future. You’ll be thankful for this if you ever lose your phone.

After filling in the questions, the “Next” button becomes active. Go ahead and click it.

Clicking “Done” takes you back to the account settings screen. You can see the Two-step authentication button has change from “Setup” to “Disable.”

That’s it! You’re now set up with extra security on your Xero account.

