Skip to content

Two-factor authentication for your account

Your firm's profile on VerifiedLawFirms is a public record that clients read before they call you. The account behind that profile controls what the page says, which reviews you respond to, and which plan you hold. Two-factor authentication adds a second lock to that account. This article explains what it is, how to turn it on with an authenticator app, how signing in changes afterward, and what to plan for so you never get locked out.

What two-factor authentication is

A password is one factor. It is something you know. Two-factor authentication asks for a second factor, which is something you have: a short code generated by an app on your phone. VerifiedLawFirms uses the TOTP method, which stands for time-based one-time password. The app produces a fresh six-digit code every thirty seconds. To sign in, you enter your email, your password, and the current code.

The code is generated on your device. It is not sent by text message, and it does not travel over email. That matters because it means an attacker needs your phone as well as your password. A stolen password alone will not get them in.

Why it matters for a law firm profile

Your account holds real power over how your firm appears in the directory. Think about what sits behind the login.

  • The public profile that potential clients read, including your name, address, phone, and website.
  • Pending edits to those critical fields, which are applied on the next editorial publish.
  • Your responses to published client reviews.
  • Your verification workspace at /account, where you upload evidence for each check.
  • Your plan tier, whether that is Basic, Pro, or Premium.

If someone takes over the account, they could post a review response in your firm's name or change the contact details a client would use to reach you. The documents you upload stay private to the editorial team, so those are not exposed through the public page. Still, the account itself is worth protecting. Two-factor authentication is the simplest way to raise the cost of a break-in.

One point to keep clear. Turning on two-factor authentication does not change your placement, and it does not grant any badge. Placement order is by plan tier, then by validated-review rating within that tier. Verification is a separate, editor-run process. Security settings sit apart from all of that. This feature protects the account and nothing more.

What you need before you start

You need two things. The first is an authenticator app installed on a phone or tablet. Common choices include Google Authenticator, Microsoft Authenticator, and Authy, though any TOTP app works. The second is your current account password, because VerifiedLawFirms asks you to confirm it before the change takes effect.

Set aside five minutes and keep your phone within reach. The setup runs in one sitting.

Enabling it with an authenticator app

The flow has a few short steps. Here is the order you will follow.

Scan QRauthenticator appEnter codeconfirms setupSign-inspassword + codeDisableneeds passwordTOTP codes rotate every 30 seconds and live only on your device.

Step 1: Open your security settings

Sign in and go to your account workspace at /account. Find the security section and choose the option to enable two-factor authentication. The page will start the setup and show you a QR code.

Step 2: Scan the QR code

Open your authenticator app and add a new account. Most apps have a plus button or a scan option. Point the camera at the QR code on your screen. The app reads it and creates an entry for VerifiedLawFirms. From that moment the app shows a six-digit code that refreshes every thirty seconds.

If the camera will not scan, look for a manual entry option on the setup page. You can type in the secret key by hand and the app will produce the same codes.

Step 3: Enter the confirmation code

Read the current six-digit code from your app and type it into the confirmation field on the setup page. This proves the app and the account are correctly linked. Codes expire quickly, so if the timer runs out, wait for the next one and enter that.

Step 4: Confirm with your password

Before the setting saves, VerifiedLawFirms asks for your account password one more time. This confirmation stops anyone who finds an open, unattended browser from changing your security settings. Enter your password and submit. Two-factor authentication is now active on your account.

Signing in with two-factor authentication

The next time you sign in, the process gains one extra step. You enter your email and password as usual. The site then asks for the current code from your authenticator app. Open the app, read the six digits, and type them in. You are through.

A few practical notes will save you frustration. The code changes every thirty seconds, so enter it promptly. If you fat-finger a digit, wait for the next code rather than retrying the same one. The time on your phone needs to be roughly accurate, because the code is tied to the clock. Most phones set their time automatically, and that is all TOTP needs.

You do this on every sign-in from a device that requires a fresh login. It adds a few seconds. That is the trade for a much stronger account.

Recovery considerations

Here is the honest part. If you lose access to your authenticator app and you have no way to generate a code, you can lock yourself out. The whole point of the second factor is that no code means no entry. Plan for that before it happens.

Several habits keep you safe:

  • Some authenticator apps back up their entries to a cloud account. If yours does, turn that on so a new phone can restore your codes.
  • If you replace your phone, move or re-add your VerifiedLawFirms entry before you wipe the old device.
  • Consider adding the account to a second trusted device so you are not tied to a single phone.
  • Keep the email address on your account current, since editorial contact runs through it.

If you are ever stuck without your codes, reach out to the editorial team through the help centre. Account recovery is handled by people, and identity checks take time. The faster path is to avoid the lockout in the first place. Treat your authenticator app like a key to the office. Do not lose the only copy.

Disabling two-factor authentication

You can turn the feature off from the same security section in your account workspace. Choose the option to disable two-factor authentication. As with enabling it, you confirm the change with your account password. Once you confirm, the account drops back to email and password alone, and future sign-ins no longer ask for a code.

Think before you switch it off. The most common good reason is that you are moving to a new phone and want to set the app up again cleanly. In that case, disable it, complete the move, then enable it fresh with a new QR scan. Leaving it off long term weakens the account, so keep the gap short.

After you disable it, you can delete the old entry from your authenticator app. It will keep showing stale codes until you remove it, and those codes no longer do anything.

Sensible security habits for firm accounts

Two-factor authentication is one layer. A handful of plain habits carries the rest of the weight, and none of them cost money.

Use a unique password

Your VerifiedLawFirms password should be used nowhere else. When a firm reuses one password across many services, a breach at any one of them hands attackers a key that fits several doors. A password manager makes unique passwords easy. It generates a long random string for each account and remembers it for you, so the length is no burden. Pick a manager, let it create the password, and you are done.

Decide who holds the credentials

An account can be shared informally across a firm, and that is where control slips. Decide who owns the login. Keep the list short. A managing partner and one trusted administrator is often enough. Every extra person with the password is another laptop, another phone, and another chance for the credentials to leak.

Write down who has access and keep that record current. When someone leaves the firm, change the password that day. If they held the authenticator setup, disable and re-enable two-factor authentication so their app no longer produces valid codes.

Guard the email on the account

Your account email is a recovery path and the channel the editorial team uses to reach you. Protect that inbox with its own strong password and its own two-factor authentication where the provider offers it. An attacker who owns your email can often work their way into services attached to it.

Watch what your workspace can change

Remember how edits flow. Critical fields such as name, address, website, and practice areas are held as pending changes and applied on the next editorial publish, while the live profile keeps the last approved values. Smaller fields, like your phone number, publish right away. That review step is a safety net, not a substitute for account security. Approved edits still go live. Keep the account locked down so only your firm proposes changes to your own page.

A short recap of the settings

Two-factor authentication lives in your account security section. You enable it by scanning a QR code, entering a confirmation code, and confirming your password. You sign in afterward with email, password, and a code from your app. You disable it the same way you turned it on, with a password confirmation. Pair it with a unique password and a tight list of who holds the login, and your firm's public presence rests on a solid footing.

This article is general information, not legal advice.