Experience the difference of "Elite".

Getting Started

Core Concepts

Overview

Bookings & Quotes

Damage Protection

Data Management

Deposits

Email Template Library

Fields

Guests

Hosted Websites

Integrations

Listing Site Integration

Messaging

My Account

Payment Processing

Privacy & Security

Properties

Property Management

Property Sharing

Quotes

Rates

Renter Agreements

Reporting

Reviews

Rules

Security Deposits

Suppressed Email Addresses

Tags

Taxes

Team Access

Technical Stuff

Travel Insurance

Verified Email Domains

Widgets

WordPress Plugin

Channel Management

Channel Management

API Integrations

Calendar Import/Export

Channel Bridge

Integrations

OwnerRez APIs

Payment Processing

Testing

Change Log

2023

2022

2021

2020

2019

Privacy & Security - Two-Factor Authentication

OwnerRez offers a robust two-factor authentication setting that all users can add to their accounts. Both master logins and team access (staff member) logins can use two-factor authentication at any time.

We require that all new user accounts (i.e., users that joined after this feature was released on December 8, 2022) use two-factor authentication. Shortly, all users, including historical accounts, will be required to turn it on, so please read how it works so that you can enable it and start securing your account today.

What is Two-Factor Authentication?

Over the past decade, after many high-profile and widespread major data breaches occurred on the internet (via phishing, etc.), many people have come to understand more about password security and the fact that a password alone can't keep their online profiles safe. That has led to the rise in the popularity of two-factor authentication, an additional layer of security that helps keep online accounts secure.

Two-factor authentication is an extra layer of security used to ensure that people trying to gain access to an online account are who they say they are. First, a user will enter their username and password. Then, instead of immediately gaining access, they will be required to provide another piece of information. This "second factor" could come from one of the following categories:

  • Something you know: This could be a password, PIN, answers to "secret questions," or a specific keystroke pattern
  • Something you have: Typically, a user would have something in their possession, like a credit card, a smartphone, or a small hardware token
  • Something you are: This category is a little more advanced and might include a biometric pattern of a fingerprint, an iris scan, or a voice print

With two-factor authentication, a potential compromise of just one of these factors won't unlock the account. So, the chances of someone else having your second-factor verification information are improbable even if your password is stolen or your phone is lost.

Looking at it from another angle, if an OwnerRez user uses two-factor authentication correctly, our website and app can be more confident of the user's identity and unlock the account.

Regarding the categories above, OwnerRez uses "something you know" and "something you have" as our two factors.

Enabling Two-Factor Authentication

OwnerRez supports two primary methods of two-factor authentication: email and authenticator app. By default, email authentication is the method enabled when you first turn on two-factor authentication, but you can easily switch to the authenticator app method.

All new users (i.e., users that joined after this feature was put in place) will already have email-based authentication in your account, and there is no way to turn it off. But rest assured, enabling and using two-factor authentication is very easy, and you'll be glad it's in place. When historical users first enable the setting, the email method will be automatically turned on. Still, you can upgrade your account to the mobile authenticator app-based method to gain a higher level of security.

You can only use one method - email or authenticator app - not both simultaneously. Email is the method users will start with by default. When you switch to the authenticator app method, the email method will automatically turn off. When logging in, there is no way to select "email or authenticator app" on the fly. You can only use the authenticator app or email option, not both simultaneously.

To get started, head to the My Account area and click on Safeguards.

By Email

1. From the top My Account menu, find and select the Safeguards option.

2. If you have never turned on Two-Factor Authentication, it will show as disabled. Click the Enable button.

3. You will see that Two-Factor Authentication is turned on with "Required" next to it. Below, it will show both Email and Authenticator App as the two-factor verification methods, and the Email method is enabled by default.

4. The next time you log in or change devices, you'll see a new verification screen that stops you and asks for a verification code.

You have 300 seconds (5 minutes) to enter the code before it times out. No worries if it does time out - you can request the code again. Simply click the "Send Verification Email Again" button, and the page will reset.

5. To find the Verification Code, go to your email and look for a new message from OwnerRez that includes a code.

6. Copy and paste that code into the Verification Code field and click the "Verify" button.

That's it! If the code is correct (and hasn't expired), you're good to go and will get right in. If it's been too long or the code is bad, OwnerRez will email you another one.

You'll be able to log in to OwnerRez without entering a verification code for 28 days, unless you clear your cookies or log in with a new user account. The verification process only occurs on unknown devices the first time you log in to that device or if it's been over 28 days since you last verified.

By Mobile Authenticator App

1. Using a mobile authenticator app can only be done after two-factor authentication is turned on with the email method first. So before you set up the mobile authenticator app method, follow the steps above (in the "By Email" section) to turn on two-factor authentication by email. Specifically, follow steps 1 - 3.

2. Once two-factor authentication by email is turned on, go back to the Safeguards page and click the "Enable" button next to the App method.

3. A window will open asking you to scan a QR code. You will do this with the authenticator app of your choice.

If you're wondering what authenticator app we work with, the answer is all of them! Authy, Google, LastPass, Microsoft, and so on. Most authenticator apps follow a public specification about how to decode and use the QR code information.

4. Once you scan the QR code, the app will ask you to confirm the nickname or account name, which you can do however you want. You might put "OwnerRez: [my email]" in that space to remind you which one it is. Most authenticator apps will prefill this for you.

5. After the app has added your new account, it will show you a code - that will change every 30 seconds. Copy that code into the Verification Code box in OwnerRez underneath where you saw the QR code. Click "Save."

NOTE: Don't leave this screen before you enter the verification code; otherwise, you'll need to start again at step 4 to add a valid account to your authenticator app, as the code being generated won't match the key required (and you should remove your other account first to not confuse it with the new valid one you need to add).

6. If the verification code works, the page will reload, and you'll see that app-based authentication is now enabled.

You'll also notice that the email method is hidden. This is because the app-based method is more secure and easier to use, and there is no need for email if you have the app method turned on. For that reason, once authenticator app is enabled, email is no longer available as a verification method.

Requiring Your Team to Use It

OwnerRez offers a team access feature where you can invite staff members to use your OwnerRez account via their login. These staff members can and should also use two-factor authentication for their own personal logins. Currently, there is no way to force your staff members to use two-factor authentication, but we encourage you to reach out to each of them to explain the advantages and ensure they have it turned on. In the future, we will require it of all users (including staff members), so it would be good to start to get them ready. We will also show whether the staff member has it turned on and what method they use (email, authenticator app) on the Team Access page that shows your staff invites.

Portal users (e.g., housekeepers and owners) cannot access the two-factor authentication settings. We may add it for portal users in the future, but it does not exist for those logins currently.

Common Issues & Questions

Do I have to do this every time I log in?

No. You will only be asked for a verification code the first time you log in to a new device (desktop, phone, tablet, etc.) or if it's been over 28 days since you last verified on that device. Also, if you clear the cookies on that device, OwnerRez will ask then, even if it's been less than 28 days.

Can I turn it off? I don't like this.

No, you cannot. Two-factor authentication is required for all new users, and any existing users that turn it on will not be able to turn it off. It will also be force-added to historical users in the near future. Due to the success of OwnerRez and its growing customer base, we have been targeted by phishing attacks in recent times. Attackers have tried to mine user data from OwnerRez by creating fake landing pages for users to enter their username/password into. By requiring two-factor authentication, we significantly increase the security of your account. Keep in mind the many important, private financial records that OwnerRez manages on your behalf. As with your online banking, it is essential that your OwnerRez account remains safe and protected. Two-factor authentication is straightforward to use and works flawlessly for all users.

Staff/team users can't see the Safeguards page

If you are logged in to the main account, you won't be able to access the Safeguards page for your own account. To get back to your own account, use the "Unimpersonate" button in the top-right corner to log back out of the main account into your own account.

Then you'll be able to access the Safeguards page for your own account.

Can I get my verification code via a text (SMS) on my phone?

No. Text (SMS) authentication is not currently an option. The only choice is email or an authenticator app.

I set up my two-factor authentication using a mobile authenticator app but never received my verification code.

It’s possible that your verification code was sent to an authenticator app but was sent to a native built-in app on your device rather than the authenticator app that you recently downloaded. Check your device settings to determine whether your device is using a native built-in authenticator app or another authenticator app that you downloaded.

  • iOS
    If you are using an iPhone, it is quite possible that your verification code was sent to the native built-in iOS authenticator app, Keychain. Need more help? Find, change, or delete saved passwords and passkeys on your iPhone or iPad or Mac.
  • Android
    Unless an authenticator app was part of the device factory install, Android device apps are generally open source. Check your device settings to determine whether your device is using a native built-in authenticator app or another authenticator app that you downloaded.

Can we have more than one user use an authenticator app on multiple devices?

OwnerRez does not currently support adding the authenticator on multiple devices, nor is it recommended, for the following reasons.

  • Enrolling two separate accounts is impossible because there is no way to access the initial QR code after the two-factor authentication app is configured, as the code only comes up before two-factor authentication registration.
  • Users need to use the same authenticator app with the same login. One user can’t use Authy and the other Google. 

While not recommended by OwnerRez, it is possible to install the same authenticator account on another user’s device and the verification code registration should appear in that authenticator account. This requires all users to do the two-factor authentication process together all at once at the same time to scan and use the same initial QR code.

Everything was working fine and now I can't log in.

Enabling your two-factor authentication can be tricky, especially if your inital verification code expires or if OwnerRez hasn't verified your login in a while. On the Two-Factor Authentication pop-up modal, users will see that their previous code has expired. Click on the  button (as shown below) to have OR send you another verification email.