Account Security & Two-Factor Authentication
Password management, 2FA setup with authenticator apps, recovery codes, and user preferences
What You'll Learn
- Change your password
- Set up two-factor authentication (2FA) with any authenticator app
- Manage and regenerate recovery codes
- Disable 2FA if needed
- Configure user preferences (timezone, language, date/time formats)
- Understand account deletion and the 7-day grace period
Changing Your Password
Update your password from Settings → Account. You'll need your current password to make the change.
| Field | Details |
|---|---|
| Current Password | Your existing password — verified against your account |
| New Password | Must meet minimum security requirements |
| Confirm Password | Re-enter your new password to confirm |
Setting Up Two-Factor Authentication
2FA adds an extra layer of security by requiring a code from your authenticator app every time you log in. Any TOTP-compatible app works.
Navigate to 2FA Setup
Go to Settings → Account → Two-Factor Authentication and click Set Up. A QR code and a secret key will appear.
Scan the QR Code
Open your authenticator app and scan the QR code. If you can't scan, manually enter the secret key instead.
Enter the Verification Code
Type the 6-digit code shown in your authenticator app to verify the connection. The code changes every 30 seconds.
Save Your Recovery Codes
After verification, you'll see 8 recovery codes. Save these immediately — you'll need them if you ever lose access to your authenticator app.
How 2FA Works After Setup
Every time you log in, after entering your email and password, you'll be asked for a 6-digit code from your authenticator app. You have 5 minutes to enter the code — after that, you'll need to log in again.
Recommended: 2FA is strongly recommended for all accounts. WorkCentral will prompt you to set it up after login until you either enable it or dismiss the prompt.
Recovery Codes
Recovery codes are your backup way into your account if you lose access to your authenticator app.
Recovery Code Details
Store them safely — keep codes in a password manager, a secure note, or a printed copy in a safe location.
Regenerate anytime — go to Settings → Account → 2FA → Regenerate Codes. Requires your current password. All previous codes are invalidated.
Important: If you use a recovery code to log in, regenerate your codes immediately. Used codes cannot be reused, and you want a full set of backup codes available.
Disabling 2FA
If you need to disable two-factor authentication, go to Settings → Account and click Disable 2FA. You'll need to enter your current password to confirm.
Warning: Disabling 2FA removes the extra security layer from your account entirely. Your authenticator app entry and all recovery codes are cleared. We recommend keeping 2FA enabled.
User Preferences
Customize how dates, times, and numbers are displayed throughout WorkCentral. These settings are per-user — each team member can set their own preferences.
| Setting | Options |
|---|---|
| Timezone | US/Canada zones, London, Paris, Berlin, Tokyo, Sydney, UTC |
| Language | English, Spanish, French, German |
| Date Format | Jan 15, 202601/15/202615/01/20262026-01-1515-Jan-2026January 15, 2026 |
| Time Format | 12-hour (2:30 PM), 24-hour (14:30), 12-hour lowercase, 24-hour with seconds |
| Number Format | 1,234.56 and other regional formats |
Per-user settings: Preferences are stored on your user account, not the organization. Each team member can configure their own timezone, language, and format preferences independently.
Account Deletion
Found in Settings → Account → Danger Zone. Only organization owners can delete a business account. This is a permanent action with a built-in safety net.
Confirm Deletion
Type DELETE in the confirmation field and enter your password. You can optionally provide a reason for leaving.
7-Day Grace Period
Your account enters a 7-day grace period. You'll receive an email with a cancellation link. During this time, your account is still recoverable.
Permanent Deletion
After 7 days, the account is permanently deleted. All data associated with the account is removed.
Changed your mind? Click the cancellation link in the email you received to reverse the deletion at any point during the 7-day grace period.
Your Account Is Secure
With these security features configured, your WorkCentral account is well-protected:
- Strong password with regular updates
- Two-factor authentication for every login
- Recovery codes stored safely as a backup
- Personalized display preferences for your workflow