Security and two-step verification

Passwords, two-factor authentication, backup codes and active sessions.

AODex signs you in through AO ID, AOCyber’s identity system. That is why some of this screen hands you off rather than handling it in place — your credentials live with AO ID, not with AODex.

The security screen, including two-step verification

Passwords

Set a new password for your AO ID account by email. Use Email me a link and follow it. AODex confirms with a sent state; a failure reads Could not send the link. Please try again.

Where a password is set directly, the rules are the ordinary ones: at least eight characters, and the confirmation has to match — Password must be at least 8 characters and Passwords do not match are the two things it will tell you.

If you signed up with Google and have never set a password, you may be prompted to Set a password to continue before certain actions.

Two-factor authentication

Two-factor authentication is set up on AO ID. Use Manage 2FA on AO ID — AODex does not hold the second factor itself.

At sign-in, once enabled, you are asked for a six-digit code:

  • from an authenticator app — Enter the 6-digit code from your authenticator app, or
  • by emailEnter the 6-digit code sent to your email, with a resend that confirms A new code has been sent to your email.

Backup codes

Backup Codes are the way back in when the second factor is not available. Copy them when they are shown and put them somewhere that is not the device running your authenticator.

Some accounts see Backup codes are not available on this account — that depends on how the account authenticates.

A second factor you cannot reach is a lockout. Before you enable 2FA, save the backup codes. This is the single most common way people lose access to an account.

Active sessions

Manage your active login sessions. Each entry shows the device and Last active, with Unknown device where it cannot tell.

ActionEffect
Revoke SessionSigns out that one.
Revoke Other SessionsSigns out everything except where you are now.
Revoke AllSigns out everything.

No other sessions to revoke means you are only signed in here.

Revoking other sessions is the correct first move if you think someone else has access — do that before changing the password, so the change cannot be undone from a session you left open.