"Keep Me Signed In" — MFA Device Trust

Purpose Understand how Keep me signed in remembers a trusted device and affects MFA prompts.
Best for Cloudbeds PMS users who sign in regularly from a personal device.
Use this when You want Cloudbeds to remember your device or need to understand why MFA is requested again.
Requirements Complete MFA and use a personal device that is not shared with other people.
Expected result Cloudbeds can skip MFA during later logins from the trusted device while its trust window remains active.
Limitations Device trust does not prevent session timeout or bypass step-up authentication. High-risk logins may not receive a trust window.

Introduction

When you complete Multi-Factor Authentication (MFA) on a device, Cloudbeds can remember that device so you are not asked to verify again every time you log in. This is the Keep me signed in feature.

Device trust applies to the device used during login and remains subject to Cloudbeds' security evaluation. Review how the trust window works and when MFA may still be required before selecting the option.

Table of contents

How Keep me signed in works

After MFA is completed, you may see a Keep me signed in option on the login screen. If you select it, Cloudbeds remembers your device and skips MFA verification during later logins from that device for as long as the trust window lasts.

The login screen shows the option that allows Cloudbeds to remember the device:

Cloudbeds login screen showing the Keep me signed in option after MFA verification

Device trust is stored per device, not per network. If you log in from the same laptop every day on a network that changes its IP address frequently, the trust still applies.

How long device trust lasts

The time before MFA is required again depends on whether your login looks familiar or unusual to Cloudbeds' security system. Cloudbeds sets the duration automatically; users cannot select it.

Login pattern When MFA is required again
Normal: familiar device and location Up to 30 days
Unusual: new or unrecognized location Up to 7 days
High risk: unfamiliar device and location Every login; no trust window

 If a login comes from a new device or location, or shows another unrecognized pattern, the trust window may be shorter or MFA may be required every time. This is expected behavior.

What device trust does not affect

Selecting Keep me signed in does not keep you permanently logged in. Your session still times out after 8 hours of inactivity. You must log in again, but you will not be asked for MFA if the device is still trusted.

Device trust also does not affect step-up authentication, the additional MFA prompt that appears before sensitive actions such as exporting data or changing your email address. Step-up authentication prompts are separate and are not skipped by device trust.

Using Keep me signed in on shared computers

 Do not select Keep me signed in on a shared computer. Use this option only on a personal device that no one else uses.

On a shared front desk terminal, selecting Keep me signed in could allow the next person who opens the browser to log in without completing MFA verification under your account.

If MFA is required at every login

If you are always prompted for MFA after selecting Keep me signed in, your recent logins may have triggered the high-risk pattern. This is not an error; it means Cloudbeds detected an unusual combination of a new device and a new location during login.

The behavior will normalize as Cloudbeds recognizes your regular login patterns over time. If the issue persists and affects your workflow, contact Cloudbeds Support.


Now that you understand how device trust affects MFA prompts, review these resources for login guidance, available MFA methods, and step-up authentication:

Was this article helpful?
0 out of 0 found this helpful

Comments

0 comments

Please sign in to leave a comment.