--- title: "Sign-in & security" slug: "sign-in-security" updated: 2026-08-20T06:46:57Z published: 2026-08-20T06:46:57Z canonical: "docs.connect.visma.com/sign-in-security" --- > ## Documentation Index > Fetch the complete documentation index at: https://docs.connect.visma.com/llms.txt > Use this file to discover all available pages before exploring further. # Sign-in & security The Sign-in & security page is where you manage everything about how you sign in to Visma: passkeys and passwordless sign-in, your password, two-factor authentication (2FA), and your electronic ID. ## Passkeys Passkeys are a fast, phishing-resistant way to sign in using your device's own security: Touch ID, Face ID, Windows Hello, or a hardware security key. Instead of typing a password, you approve the sign-in the same way you unlock your device. ### Adding a passkey 1. Find the **Passkeys** section and click **Add passkey**. 2. Your browser will prompt you to create the passkey with your fingerprint, face, PIN, or security key. 3. Give the passkey a name you will recognize later, for example "Work laptop" or "Personal phone". Depending on your device, the passkey may sync across your other devices through your platform account (such as your Apple or Google account), so you can often use the same passkey on your phone and laptop. You need a reasonably recent browser to use passkeys; if the Add passkey button does not respond, updating your browser usually resolves it. ### Managing your passkeys Each passkey shows when it was added and last used. Click **Remove** next to a passkey you no longer need, for example after replacing a device. Removing a passkey does not sign you out, but that device can no longer use it to sign in. ### Going passwordless Once you have at least one passkey, you can remove your password entirely and make passkeys your only way to sign in. This is the strongest protection available for your account, because there is no password left to guess, leak, or phish. 1. In the **Passkeys** section, turn on the **Passwordless** toggle. 2. Confirm in the dialog. While passwordless is on, your password is disabled and your saved two-factor authentication settings are suspended (a passkey already proves your identity with the device itself). Nothing is deleted: if you later turn passwordless off, your password and two-factor settings are restored exactly as they were. **We recommend having passkeys on all your devices before going passwordless, so you never lock yourself out.** ## Password 1. In the **Password** section, click **Change password**. 2. Enter your current password, then your new password twice. The dialog shows the password requirements as you type. Your new password cannot be one you have used recently, and known-breached passwords are rejected for your protection. The section always shows when your password was last changed. If you have gone passwordless, there is no password to change; the section shows that passkeys are being used instead. ## Two-factor authentication (2FA) Two-factor authentication adds a second step when you sign in, so a stolen password alone is never enough to access your account. ### Turning on two-factor authentication 1. In the **Two-factor authentication** section, turn the switch on. 2. You are guided through setting up your first method: scan the QR code with an authenticator app (such as Microsoft Authenticator, Google Authenticator, or 1Password) and enter the 6-digit code it shows. From then on, sign-ins ask for a second step. Some organizations require 2FA for all users; in that case the switch is locked on and shows a note that your organization requires it. ### Your 2FA methods Once 2FA is on, you can manage the individual methods: - **Authenticator app**: 6-digit codes from an authenticator app. This is your base method. You can register the same account on an additional device: click **Add device**, enter a code from your existing app to authorize it, then scan the new QR code with the new device. The QR code and secret are shown only once. - **SMS verification**: receive codes by text message. Requires a verified phone number, which you manage on your Profile page. - **App prompt (Visma Authenticator)**: approve sign-ins with one tap on your phone. Click **Add device** to pair the Visma Authenticator app; you will be guided through the pairing during a short sign-in flow. - **Security key**: use a hardware key (such as a YubiKey) as your second step. - **Recovery code**: a one-time code that gets you in if you lose access to your other methods. Generate it, store it somewhere safe (a password manager is ideal), and note that generating a new one replaces the old one. The code is shown only once. Availability can vary: the application you opened Account Settings from may not offer every method, in which case the methods it does not use are not shown. If you chose to be remembered on a device during sign-in, a **Remember me** entry appears here, and you can revoke it so that device asks for 2FA again. ### Turning off two-factor authentication 1. Turn the switch off. 2. Confirm with a 6-digit code from your authenticator app. If you have lost your device, switch the dialog to recovery-code mode and use your recovery code instead. If your organization enforces 2FA, it cannot be turned off. ### Lost your 2FA device? Use your **recovery code** to confirm the disable dialog, then set 2FA up again on your new device. If you have no recovery code either, contact your organization's administrator or Visma support. ## Electronic ID An electronic ID (eID) is a government-grade digital identity issued in your country, such as BankID or MitID. Linking one to your Visma account lets applications that require strong identification verify who you are, and gives you a highly secure way to sign in. The provider offered depends on the country set on your profile: - **Norway**: BankID (including BankID with biometrics) - **Sweden**: BankID - **Denmark**: MitID - **Finland**: BankID If your country has no supported provider and you have no linked identity, the section is not shown. ### Linking your electronic ID 1. Find the **Electronic ID** section and click **Add national identity**. 2. You are sent to your country's identity provider to authenticate the way you normally do (for example with your BankID app). 3. After a successful authentication you return to Account Settings, and the identity shows as linked with the date it was added. ### Removing a linked identity Click **Remove** next to the linked identity and confirm. You can re-link it at any time by authenticating with the provider again. If you have identities linked in more than one country, each one is listed and can be removed individually.