Skip to main content

How to Activate Your Caruso Account and Set Up MFA

Setting up additional security measures

Fahim Kaidawala avatar
Written by Fahim Kaidawala
Updated over 2 weeks ago

Caruso uses Single Sign-On (SSO) with Microsoft or Google, along with Multi-Factor Authentication (MFA), to provide a secure login experience for all users. Follow the steps below to activate your account and set up MFA.


Step 1: Activate Your Account

  • Look for an activation email invitation from Caruso.

  • Click the activation link in the email to accept your invitation.

  • If you have not received the email, contact a member of your Caruso admin team for support.


Step 2: Select Your Authentication Method

On the Caruso login page, you can sign in using one of the following options:

  • Google

  • Microsoft

  • Email address

  • Use passkey instead (if this has been enabled on your account)

If you are unsure which option to use, please contact your Caruso admin team for guidance.


Step 3: Set Up Multi-Factor Authentication (MFA)

Caruso requires MFA to enhance account security.

Download an Authenticator App

  • You will need an authenticator app to complete this process. You can either use an internal app provided by your organisation or download one of the commonly used options from your smartphone’s App Store or Google Play Store, such as:

    • Microsoft Authenticator

    • Google Authenticator

Log in and Access Security Settings

  • Log in to the Caruso Admin Portal.

  • Select your username in the top-right corner.

  • Select Profile.

  • Select Security from the left-hand menu.

Add Two-Step Verification

  • Select + Add two-step Verification.

  • Open your authenticator app and select Add Account (or tap the + icon).

  • Scan the QR code displayed on the screen.

  • Enter the one-time password (OTP) from your app to complete the setup.


Set Up Microsoft or Google Authenticator

Using Microsoft Authenticator

1. Download the Microsoft Authenticator App

  • For iOS (iPhone/iPad): Either search and download from the App store or use the link here.

  • For Android: either search and download from the Google Play Store or use the link here.

2. Open the Microsoft Authenticator App

  • Launch the app from your home screen. You might need to grant the app permission to access your camera for QR code scanning.

3. Add Your Account to Microsoft Authenticator

  • Option A: Scan a QR Code:

    • Log in to the account you want to secure (e.g., Microsoft account, Gmail, Facebook, etc.).

    • Navigate to the security settings or two-factor authentication section of the account. This is usually found in the account settings or security settings.

    • Look for the option to “Set up two-factor authentication” or “Enable 2FA”.

    • Choose the option to “Set up using an app” or “Scan a QR code”.

    • You’ll be shown a QR code on the website.

    • Open the Microsoft Authenticator app and tap the “+” icon or “Add account”.

    • Select “Personal account” or “Work or school account”, depending on the type of account you’re adding.

    • Choose “Scan a QR code”.

    • Point your phone’s camera at the QR code displayed on the website. The app will automatically recognize the code and add the account.

  • Option B: Manual Entry

    • If the website provides a manual setup option, you will receive a secret key (a string of characters).

    • In the Microsoft Authenticator app, tap the “+” icon or “Add account”.

    • Select “Other account” (Google, Facebook, etc.) or “Enter a setup key”.

    • Enter the account name (e.g., “Gmail” or “Facebook”) and the secret key provided.

    • Choose whether to set up the account as “Time-based” or “Counter-based” (usually “Time-based”).

4. Complete the Setup

  • Once the account is added to the app, you’ll see a 6-digit code generated every 30 seconds.

  • Enter the 6-digit code into the account setup page on the website to complete the setup.

Using Google Authenticator

1. Download the Google Authenticator App

  • For iOS (iPhone/iPad): Either search and download from the App store or use the link here.

  • For Android: either search and download from the Google Play Store or use the link here.

2. Open the Google Authenticator App

  • Launch the app from your home screen. You’ll be greeted with a welcome screen if it’s your first time using the app.

3. Set Up Your First Account

  • Option A: Scan a QR Code

    • Log in to the account you want to secure (e.g., Gmail, Facebook, or any service that supports 2FA).

    • Navigate to the security settings or two-factor authentication section of the account. This is usually found in the account settings or security settings.

    • Look for the option to “Set up two-factor authentication” or “Enable 2FA”.

    • Choose the option to “Set up using an app” or “Scan a QR code”.

    • You’ll be shown a QR code on the website.

    • Open the Google Authenticator app and tap the “+” icon or “Begin setup” (this might be different depending on the version of the app).

    • Select “Scan a barcode” or “Scan QR code”.

    • Point your phone’s camera at the QR code displayed on the website. The app will automatically recognize the code and add the account.

  • Option B: Manual Entry

    • If the website provides a manual setup option, you will receive a secret key (a string of characters).

    • In the Google Authenticator app, tap the “+” icon or “Begin setup”.

    • Choose “Enter a provided key” or “Manual entry”.

    • Enter the account name (e.g., “Gmail” or “Facebook”) and the secret key provided.

    • Choose whether to set up the account as “Time-based” (usually the default) or “Counter-based” (less common).

4. Complete the Setup

  • Once the account is added to the app, you’ll see a 6-digit code generated every 30 seconds.

  • Enter the 6-digit code into the account setup page on the website to complete the setup.


Removing or Resetting MFA

If you change your device or need to remove your existing MFA configuration for another reason, please contact Caruso Support.

  • Email [email protected] to request an MFA reset or removal.

  • Once reset, you will be prompted to reconfigure your two-factor authentication at your next login.


MFA Timeouts and Re-authentication

  • Admin users must complete MFA each time they log in

  • Once authenticated, you will remain logged in for up to 14 days

  • If inactive for 24 hours, you will be prompted to re-authenticate


If you have any questions or need help at any stage, please contact our Caruso Support team either by email or live chat.

Did this answer your question?