Two-factor authentication (2FA / TFA), often referred to as two-step verification, is a security process in which the user provides two authentication factors to verify they are who they say they are. FFA can be contrasted with single-factor authentication (SFA), a security process in which the user provides only one factor -- typically a password.
Two-factor authentication provides an additional layer of security and makes it harder for attackers to gain access to a person's devices and online accounts, because knowing the victim's password alone is not enough to pass the authentication check.
Activation Server 6 supports for the second identification step google authenticator or any software which supports one time passwords (e.g. 1Password, Authy). One time passwords are time-dependent six-digit codes, which you enter after you submit your user name and password
The Two-Factor Authentication can only be enabled by the administrator in Administration / Setup - Company Information
Download the Google Authenticator Android / Iphone or Ipad (free) or apps which run on Windows, macOS or even apple watch like 1Password or Authy.
If you login the first time after TFA was enabled, you have to scan a barcode. Alternatively you can manually type in the setup code.
If the barcode scan is successful you get a 6 digit validation code which you enter in the field and click on the button: Validate My Code
If you loose your device, the administrator can reset your TFA. Some apps make backups which you can restore on a new device. However a good practice is to create recovery codes and store it in a save location. A recovery code can be used only once.
Click on the button Generate Recovery Codes
This will generate a text file which you can download. It includes 8 codes which you can use only once.
After providing user name and password and validating the password, a second screen appears to provide the 6 digit code from the authenticator app.
The user will get an e-mail which confirms that the TFA setup is now active.