Multi-Factor Authentication - Everything you need to know

Cloudbeds uses multi-factor authentication (MFA) to provide a strong and flexible security solution for your account. MFA adds an important layer of protection, making it significantly more difficult for unauthorized individuals to access your account and sensitive information.

You can choose from several authentication methods based on your devices, security needs, and preferred login experience.

  You do not need to be technical to use MFA. You can change your authentication method at any time or reset multi-factor authentication when needed.

Additional verification for sensitive actions

Some sensitive actions in the Cloudbeds Dashboard require an additional identity check, known as step-up MFA. This extra verification helps protect important account settings and property data, even when a user is already signed in.

Sensitive actions are unavailable for 10 minutes after login

  During the first 10 minutes after you log in, sensitive Dashboard actions are temporarily blocked. Step-up MFA verification is not offered during this period.

If you attempt one of these actions, you will see an on-screen message explaining that the action was declined. Wait until the 10-minute window has passed, and then try the action again.

After the first 10 minutes of your session, the normal verification process applies. When you attempt a sensitive action, you may be asked to complete an MFA verification before continuing.

Sensitive actions include:

  • Exporting reservations to an XLS file
  • Resetting your own MFA method
  • Resetting another user's MFA method, when permitted
  • Editing custom JavaScript or HTML in the Booking Engine

After you successfully complete step-up MFA, the verification remains valid for 8 hours, provided that you continue using the same user account, property, and network.

  Why is there a delay? The 10-minute security window helps protect your account from phishing attacks in which an attacker attempts to use a stolen login and immediately relay an MFA prompt to perform a sensitive action.

Choose an MFA method

Select the authentication method that provides the best balance of security and convenience for your setup.

Which method is right for you?

If you... Recommended option
Use an iPhone, iPad, or Mac Apple Login — a fast and convenient option
Use Gmail or an Android device Google Login — a fast and convenient option
Want the strongest phishing-resistant protection Passkeys — the gold standard
Prefer to enter a rotating verification code Authenticator app

  A note on SMS, Email, and Voice: These methods are available to all users and can be useful as account recovery options — particularly Email, which is now automatically enabled for all users as a fallback if you lose access to your primary device. They are not recommended as your primary login method. If you currently rely on SMS or Email to log in, we encourage you to switch to one of the methods in the table above when convenient. See: Reset Multi-Factor Authentication

Our top recommendations

We recommend the following methods for the best balance of security and ease of use.

1. Social login with Apple or Google

One of the simplest ways to securely access Cloudbeds is to link your existing Apple or Google account.

  • Why choose this method? You can use the secure login method you already use with Apple or Google instead of managing another separate login method.
  • Easy to use: After setup, select the corresponding Apple or Google option when you sign in.

Setup instructions:

2. Passkeys: The gold standard

A passkey is a highly secure way to log in. Think of it as a digital key stored on your device.

  • How it works: Instead of entering a password, you approve your login using the method you already use to unlock your phone or computer, such as your fingerprint, Face ID, or device PIN.
  • Phishing-resistant: A passkey is linked to the legitimate Cloudbeds website and cannot be entered into a fraudulent login page like a password or verification code.
  • Private: Your biometric information, such as your fingerprint or face scan, remains on your device and is not shared with Cloudbeds.

3. Authenticator apps

An authenticator app, such as Google Authenticator, Okta Verify, Microsoft Authenticator, or 1Password, generates a six-digit verification code that changes approximately every 30 seconds.

  • Why choose this method? Even if someone obtains your password, they generally cannot access your account without the current verification code from your authenticator app.
  • Works without SMS: The verification code is generated directly in the app and does not rely on a text message.

Alternative MFA methods

If the recommended options above do not fit your setup, you can also use another supported MFA method.

  • Okta Verify
  • Google Authenticator or another TOTP authenticator app, such as Microsoft Authenticator or 1Password
  • Other supported MFA methods
  • SMS, Email, and Voice are now available to all users as verification and account recovery options. All users have also been automatically enrolled in Email verification as a fallback — if you lose access to your primary MFA device, your registered email can be used to recover access. These methods are available but not recommended as a primary login method due to the security limitations described above.

  Need to change your method? You can change your MFA method in your security settings. When necessary, follow the steps to reset multi-factor authentication.

Was this article helpful?
0 out of 0 found this helpful

Comments

2 comments
  • It would be best if Org Owners can determine which MFA methods are possible for all org users. For example, if the org decided that no users can use email, phone, or voice for authenticating. 

    0
  • Hello, Ryan Murfit,

    Thank you so much for your suggestion. 

    We have already escalated your comments to our dedicated Product team for review. 

    Have a great day 💛

    0

Please sign in to leave a comment.