How to Sign In with a Code from Your Authenticator App
If your company uses two-factor authentication, signing in to ABM Service in a browser takes two steps: your ABM password, then the six-digit code your authenticator app is showing. After a right password, the sign-in page changes to Enter your code, where you type the code and select Sign in. The ABM Service desktop app never asks for a code.
How do I sign in with my authenticator code?
After your password is accepted, the ABM Service sign-in page shows Enter your code with a box labelled Authenticator code. Open your authenticator app on your phone, find the ABM Service entry for your company, type the six digits it is showing now, and select Sign in.
- Sign in with your name and ABM password on the sign-in page, as usual.
- Open your authenticator app on your phone and find the entry named ABM Service with your company and your name.
- Type the six digits it shows in the Authenticator code box on the Enter your code screen. On a phone, the box offers a number keypad, and some phones offer the code for you.
- Select Sign in, or press Enter in the Authenticator code box. The button reads Signing in… while the code is checked, and then ABM Service opens.
The box takes digits only; anything else you paste in is dropped, and it stops at six. If you select Sign in with fewer than six digits, the page says Enter the six-digit code from your authenticator app.
The code in your app changes every thirty seconds. If it is about to change, you can wait for the next one; a code that has only just changed is still accepted for a short while.
You have five minutes from a right password to type a right code. After that the page says That took too long. Sign in again. and goes back to the name and password.
When does ABM Service ask me for an authenticator code?
ABM Service asks for a code only when you sign in to it in a browser, and only if your company uses authenticator apps. It does not ask every morning: once you are signed in, you stay signed in on that browser for thirty days after you last used it.
Your system administrator decides, for the whole company, whether authenticator apps are used, with a setting that has three choices:
- Off: nobody is asked for a code, and the menu has no Authenticator entry.
- Optional: anybody may set up an authenticator app from the menu, and only people who have set one up are asked for a code.
- Required: everybody must have one. Somebody who has not set one up is taken to set it up straight after their password, and cannot open ABM Service until they have.
So you meet the code step after you select Sign out, when you sign in on a new browser or computer, after thirty days without using ABM Service on that browser, and after ABM Service has been restarted on your company's server, which signs everybody out.
When your system administrator changes this setting, nobody is signed out. You meet the new rule at your next sign-in.
The ABM Service desktop app does not use authenticator codes at all; it has its own sign-in window.
Why was my authenticator code not accepted?
That code was not accepted. Check your authenticator app and type the code it is showing now. means the six digits were not the right code at that moment. ABM Service empties the Authenticator code box; type the code your app is showing now and select Sign in again. You do not need to type your password again.
The usual reasons are:
- The code changed while you typed it. Type the new one.
- You used a code twice. Each code works once. If you have just used a code, for example to set up your app, wait for the next one.
- You used the wrong entry. If you work for more than one company, your app has one ABM Service entry per company, and each only works for its own company. Check the company name on the entry.
- Your phone's clock is wrong. Codes depend on the time. If every code is refused, check that your phone sets its date and time automatically. If it does and codes are still refused, tell your system administrator.
A wrong code is answered after a short wait, which grows with each wrong code, and with any wrong password you typed before it: one second, then two, then four, up to half a minute. The page reads Signing in… while it waits. This slows down anyone guessing; it is not a lock-out, and the waits are forgotten once you have signed in.
If the page says That took too long. Sign in again., more than five minutes have passed since your password was accepted. Sign in again with your name and password, then type a fresh code.
What do I do if I have lost my phone or have a new one?
If you have lost the phone with your authenticator app on it, you cannot sign in to ABM Service in a browser until your system administrator resets your authenticator. What happens at your next sign-in after the reset depends on your company's setting:
- When authenticator apps are required, ABM Service takes you straight to setting up an authenticator app again after your password, and you set it up on your new phone.
- When authenticator apps are optional, your password alone signs you in. Set up an authenticator app again on your new phone from Authenticator in the menu if you want to keep using one.
A lost phone does not stop you working in a browser where you are already signed in to ABM Service, and the reset does not sign you out there: the reset only makes a difference the next time you sign in.
If you still have your old phone and are moving to a new one, what you do depends on your company's setting:
- When authenticator apps are optional, sign in, open the menu, select Authenticator, turn your authenticator off with a current code from your old phone, and then set one up again with your new phone.
- When authenticator apps are required, you cannot turn yours off yourself. Ask your system administrator to reset it, and set it up on the new phone at your next sign-in.
There are no printed backup or recovery codes for ABM Service.
If ABM Service tells you your authenticator needs setting up again although nothing has happened to your phone, your company's ABM Service has moved to another server or its database was restored elsewhere. Scan the new square it shows and you are back as you were.