How to Set Up an Authenticator App for ABM Service
An authenticator app on your phone adds a second step to signing in to ABM Service in a browser: after your password, you type the six-digit code the app shows. You set it up once on the Set up your authenticator screen, either straight after your password when your company requires one, or from Authenticator in the menu when it is optional.
How do I set up an authenticator app when ABM Service asks me at sign-in?
When your company requires an authenticator app and you do not have one set up, ABM Service shows Set up your authenticator straight after your password is accepted. You scan the square with your phone, type the code the app then shows, and select Confirm and sign in; that one step both saves your authenticator and signs you in.
- Install an authenticator app on your phone if you do not have one. Google Authenticator, Microsoft Authenticator, 1Password or any other authenticator app will do.
- Sign in with your name and ABM password. The page changes to Set up your authenticator and shows preparing a new secret… for a moment.
- Scan the square on the Set up your authenticator screen with your authenticator app. If you cannot scan it, type the key shown under Or type this key into the app instead.
- Type the six-digit code the app now shows into The code it shows box.
- Select Confirm and sign in. The button reads Checking… while the code is checked, and then ABM Service opens on the screen you were going to.
Nothing is saved until the code is right, so a scan that did not work costs nothing: scan again or type the key, and try a new code. The screen has no way to skip this step when your company requires an authenticator. You have five minutes from your password to finish; after that the page says That took too long. Sign in again., and you sign in and scan a new square.
From then on, every time you sign in you type the code your app shows after your password.
How do I set up an authenticator app from the menu?
When your company has made authenticator apps optional, you can set one up whenever you like. Open the menu, select Authenticator on the row under your name, then select Set up on the Your authenticator page and follow the same screen as at sign-in, finishing with Turn it on.
- Open the menu and select Authenticator, beside Sign out under your name.
- Select Set up on the Your authenticator page.
- Scan the square with your authenticator app, or type the key shown under Or type this key.
- Type the six-digit code the app shows into The code it shows box.
- Select Turn it on. The page says Your authenticator is set up. and shows the date it was set up.
- Select Back to the application to return to the screen you came from.
If you change your mind before typing a code, select Cancel: nothing has been saved and you are back on the Your authenticator page as you were. If you take more than five minutes, the page says That took too long. Start again.; select Set up again to get a new square.
You stay signed in while you do this. The new authenticator is asked for the next time you sign in, for example after you sign out or on another browser.
When your company requires authenticator apps and you have none, the Your authenticator page says so, and offers Set up too. If you do not use it, you are asked to set one up at your next sign-in anyway.
What if I cannot scan the square with my phone?
If your phone cannot scan the square on the Set up your authenticator screen, for example because you are using ABM Service on the same phone, type the key instead. The key is shown under Or type this key, beside the square, in groups of four letters and numbers.
- Choose the option in your authenticator app to add an account by entering a key, often called enter a setup key or enter code manually.
- Type the key exactly as shown under Or type this key. The spaces between the groups do not matter. Select Copy to copy the key to your clipboard if you want to paste it; the button reads Copied for a moment.
- Choose a time-based code if your app asks which kind.
- Type the six-digit code the app then shows into The code it shows box and finish as usual.
If the square itself cannot be drawn, the screen says The square could not be drawn — type the key instead. The key works exactly like the square.
Keep the key private, the same as a password. Anyone who has it can produce your codes. You do not need to write it down: if you lose your phone, your system administrator resets your authenticator and you set up a new one.
What will my authenticator app call the ABM Service entry?
Your authenticator app saves the entry under your company's name and your own name, marked as coming from ABM Service. The Set up your authenticator screen tells you exactly what the app will save it as, in the sentence under the square: It saves it as followed by your company's name, a colon and your name.
If you work for more than one company, you set up one entry per company, and your app shows them side by side with each company's name, so you can tell them apart. Each entry's codes work only for its own company. Setting up one company does not set up another; each company's ABM Service asks you separately.
Once the entry is saved, the app shows a six-digit code that changes every thirty seconds. That is the code ABM Service asks for when you sign in.
If you set up the same company again, for example on a new phone, the old entry in your old app stops working. You can delete it from the app.
Why does ABM Service say my authenticator needs setting up again?
If the Set up your authenticator screen says Your authenticator needs setting up again on this server, your company's ABM Service has moved to a different server, or its database was restored somewhere else, so the secret your phone shares with it can no longer be read. Nothing is lost: scan the new square, type the code, and you are back as you were.
This can happen to everybody at a company on the same morning, and it happens even when authenticator apps are optional, so that nobody who had one is quietly left with a password alone. You cannot sign in until you have set it up again.
The Your authenticator page shows the same situation as Needs setting up again, with a Set up button.
After setting up again, delete the old ABM Service entry for that company from your authenticator app, so you do not type its codes by mistake.