Setting up an authenticator app#
If you sign in to Querona with a standard account - a user name and a password that Querona itself holds, rather than your organisation’s Windows or Microsoft Entra ID account - you can add a second factor to it: a six-digit code from an authenticator app on your phone, typed in front of your password each time you sign in. You set it up yourself, from your own profile, and no permission is needed.
Your administrator may require it of your account. Your profile then says Required since a date - and until you set one up, you still sign in with your password alone. Whether that has a deadline depends on how Querona is configured; see If an authenticator is required of you below.
Before you start#
Install an authenticator app on your phone if you do not have one - Microsoft Authenticator, Google Authenticator, or any app that produces time-based codes. The app needs no network connection: the codes come from a key it stores and from the time, so the only thing that has to be right is your phone’s clock. Leave it set to automatic time.
Set it up#
Click your user name in the top-right corner. This opens My profile.
Under Authenticator app, click Set up an authenticator.
Type the password you sign in with into Current password and click Show the QR code. This proves it is you: a browser session left open is not enough to bind your account to an authenticator. A wrong password is shown against the field; correct it and try again - but not by guessing: a wrong password here counts as a failed sign-in, and repeated failures lock your account out for a while from the address you are working from, as at sign-in (see Failed sign-in lockout), after which the step is refused until the lockout passes.
In the app, add an account by scanning the QR code shown. If you cannot scan, add the account by typing the key shown under the code instead; Copy puts it on the clipboard where the browser allows that, and selects it on the screen otherwise.
Type the six-digit code the app now shows into Code from the app and click Confirm.
The QR code and the key are shown once, while this screen is open, and nothing is set up until a code is confirmed. If you change your mind, click Cancel rather than closing the screen: it tells Querona to forget the pending set-up, so a QR code someone else may have seen can never be confirmed. A set-up you only closed the screen on stays pending - it cannot be used to sign in, and your administrator sees it as Enrolment pending - and your profile says so the next time you open it, offering to discard the pending set-up; do that, or click Set up an authenticator again, which replaces it with a new QR code. An administrator’s reset drops it too. When you start again, remove the old account from the app, because only the codes of the latest key are accepted.
If the code is refused, wait for the app to show the next one and try that; the screen keeps the same QR code. If several in a row are refused, check the phone’s clock. If the screen says instead that the set-up was interrupted - for example because an administrator reset your authenticator while the QR code was showing - the QR code is gone for good; start again from Set up an authenticator if you still want one.
Signing in afterwards#
From now on, wherever you sign in with your password, type the six-digit code from the app first and your
password directly after it, in the password box, with nothing in between. If the app shows 123456 and
your password is Winter-2026, the password box takes:
123456Winter-2026
That is all that changes. There is no second prompt, so this works in any SQL client - in SQL Server Management Studio it is the Password box of the Connect to Server dialog - as well as in the Querona web interface and wherever a program asks Querona for an access token with your password.
A code is good for its own thirty seconds, and the code before and the code after it are accepted too, so up to half a minute either side. Using a code does not spend it: a connection pool that reopens connections with what you typed keeps working while the code lasts. A tool that saved what you typed and reconnects on its own later is refused, because the code has expired by then; the second factor is meant for accounts a person signs in with.
If the code is refused#
A wrong code and a wrong password are refused the same way, and the refusal does not say which was wrong. Check that:
the code is the one the app shows now - it changes every thirty seconds;
the code comes first, then the password, with no space or other separator;
the phone’s clock is right - a clock that is off by a minute produces codes Querona rejects.
Each refused attempt counts as a failed sign-in, and repeated failures lock your account out for a while from the address you are signing in from - see Failed sign-in lockout. Wait for the lockout to pass rather than guessing.
If an authenticator is required of you#
When your administrator requires an authenticator of your account and Querona is set to enforce it, you have a grace period to set one up, counted from the Required since date your profile shows. While it runs, you sign in as before, and the web interface tells you in the page header that an authenticator will be required for your account from a date, with the days left; the notice links to your profile, and you can dismiss it for the session. The header shows other notices in the same place and steps through them every thirty seconds when there are several.
Once the grace period has passed:
In the web interface you can still sign in, but you see only your profile - there is no navigation, and signing out is the only other thing you can do. The profile says that multi-factor authentication is required for your account and asks you to set up an authenticator to continue. Set it up as above; the session lasts a limited time, set by your administrator, so do it right away. When the code is confirmed, you are told to sign in again and signed out. This is the sign-in with your password: if you sign in to the web interface with your Windows account instead, you are refused with The username or password is invalid - sign in with your password to set the authenticator up.
In a SQL client you cannot sign in at all, with your password or with your Windows account: the connection is refused with Login failed for user … Reason: Multi-factor authentication is required for the account, but no authenticator has been set up yet. Set the authenticator up in the web interface, then connect with the code in front of your password.
A set-up you began and did not confirm does not count; only a confirmed one does. A refusal on this ground is not a failed guess - your password was right - so it does not count toward the failed sign-in lockout. A web session or a SQL connection you opened before the grace period ended keeps working until you sign out or disconnect; the rule is applied when you sign in.
If you lose your phone#
Ask your administrator to reset your authenticator - or, if your own account holds the Alter any login permission, reset it yourself from . There are no backup codes, and from your profile you cannot remove or replace an authenticator you have set up: while one is set up, Set up an authenticator is not offered, and only a set-up you have not confirmed yet can be discarded. After the reset you sign in with your password alone, and set up a new authenticator as above; if your administrator requires one, your profile says so, and where the requirement is enforced the grace period starts again from the reset.
What is recorded#
Starting, confirming and cancelling a set-up are recorded, and so is a refused code or password. The QR code, the key, the codes and the password you type are never written to the audit trail or to any Querona log.
See also
Administrators requiring or resetting an authenticator: Second factor.