Carga

Two-factor sign-in challenge

Use this screen when Actualog asks for a second factor after the password or external provider sign-in succeeds.

Authenticator-code sign-in

  1. Open the authenticator app entry for Actualog.
  2. Enter the current six-digit code.
  3. Select Continue.

Codes expire quickly. If a code is rejected, wait for the next code and try again.

Trust this browser

Select Trust this browser for 30 days only on a private device you control. A trusted browser can skip the authenticator-code prompt after a successful first factor during the trust period. The trust applies to the same browser profile across Actualog language domains for the same account.

After the code succeeds, ASP.NET Core Identity writes its protected remembered-browser cookie. You can check or revoke the current browser later from Two-factor authentication settings.

After you complete MFA, normal session refresh should preserve that MFA assurance while you remain signed in. Actualog should not ask for another authenticator code during ordinary navigation unless the session expires, the browser trust is revoked or missing, or you start a sensitive action that requires fresh MFA.

If Actualog asks for an authenticator code again, open the settings page and check the current-browser status. The browser must keep the Identity cookie for this to work. Private/InPrivate windows, a different browser profile, or a setting that clears cookies/site data when the browser closes will remove the proof and require MFA again. Actualog cannot safely reconstruct missing browser proof from the password, browser name, IP address, or a server record.

Microsoft Edge: keep trusted-browser proof

Microsoft Edge can be configured to delete cookies whenever it fully closes. This may look intermittent because closing one window does not always stop every Edge process, while a Windows restart closes the browser completely.

To check the setting:

  1. Open edge://settings/privacy/clearBrowsingData/clearOnClose in Edge.
  2. Find Cookies and other site data under Choose what to clear every time you close the browser.
  3. A green/on switch means Edge will delete the Identity trusted-browser cookie when Edge closes.
  4. Turn the switch off if cookies should remain for every site. If you want Edge to continue clearing other sites, keep the switch on and use Don't clear → Add to retain the Actualog parent domain shown in the address bar.
  5. Complete MFA once more with Trust this browser for 30 days if Edge already deleted the previous cookie.

Changing language inside Actualog does not revoke browser trust. The same protected cookie is configured for Actualog's language subdomains. Application restart also does not revoke it while the browser retains the cookie and the account security stamp remains valid.

A trusted browser does not:

  • bypass the password;
  • create or change roles;
  • bypass fresh MFA checks for sensitive actions;
  • apply to other browsers, profiles, devices, or private/incognito windows.

Recovery-code sign-in

If your authenticator app is unavailable, choose Use a recovery code instead and enter one saved recovery code. Each recovery code can be used only once.

Recovery-code sign-in does not remember the browser. After using recovery codes, set up a new authenticator app or generate new recovery codes as soon as possible.