Login and security
Your organisation controls which sign-in methods are available. Local accounts use an email address and password; two-factor authentication, passkeys or single sign-on may also be offered.
Sign-in form
Example instance with sample data. Available controls depend on your role and configuration.
Sign in with an email address and password
- Enter your Email address and Password on the sign-in page.
- Select Sign in.
- If prompted, enter an authenticator code or backup code. You may be able to use a passkey instead.
- Accept the terms of use if required.
Repeated failed attempts may be temporarily limited. Follow the displayed wait time or contact your administrator.
Reset your password
- Select Forgot password? on the sign-in page.
- Enter your email address and select Send link.
- Check your inbox and open the link.
- Enter a new password of at least 12 characters twice.
- Select Set password, then sign in again.
The confirmation does not reveal whether an account exists for an address. If no email arrives, check your spam folder and the address you entered. Request a new link if the previous one has expired or was already used. Resetting your password revokes existing sessions.
Set up two-factor authentication
If your organisation requires 2FA, Intra AI guides you through setup after sign-in. You can also manage it under Settings → Security when your account type allows this.
- Select Enable 2FA, then Start setup.
- Scan the QR code with a TOTP-compatible authenticator app, or copy the setup key.
- Copy or download the displayed backup codes and store them separately from your device.
- Confirm that you have saved the codes.
- Enter the six-digit code from the app and select Enable 2FA.
At sign-in, select Use backup code to enter a single-use backup code. If you have neither your app nor a backup code, ask your administrator for help.
Depending on policy, Settings → Security also lets you enrol an authenticator again, generate replacement backup codes or disable 2FA. New backup codes replace the old set.
Security settings for two-factor authentication and passkeys
Example instance with sample data. Available controls depend on your role and configuration.
Use passkeys
Passkeys use your device security, such as a fingerprint, face recognition, device PIN or hardware security key. They appear only when the feature is available for your organisation and browser.
Add a passkey
- Open Settings → Security.
- In Passkeys, select the option to add one.
- Confirm your identity if prompted.
- Optionally enter a recognisable name.
- Follow the prompt from your browser or operating system.
You can register several passkeys, then rename or remove them in the security settings. Do not remove your last available sign-in method.
Sign in with a passkey
If passwordless sign-in is enabled, select Sign in with passkey on the sign-in page and follow the device prompt. Some browsers also offer stored passkeys in the email field.
Use single sign-on
If you see Sign in with [provider]:
- Select the button.
- Sign in with your organisation’s identity provider.
- After successful verification, you return to Intra AI.
For SSO accounts, the identity provider often manages the password, MFA and profile details. The related Intra AI settings may therefore be hidden.
Review active sessions
Open Settings → Sessions to review signed-in devices and browsers.
- Revoke an unfamiliar or unneeded session from its row.
- Select Sign out all others to end every session except the one you are using.
- Use Sign out in the account menu to end the current session.
If you do not recognise a session, revoke it and change the password for a local account. Tell your administrator as well.
Common problems
| Problem | What to do |
|---|---|
| The SSO or passkey button is missing | The method may be disabled or unsupported by your browser. |
| An authenticator code is rejected | Check your device clock and try the next code. |
| A backup code fails | Each backup code can be used only once. |
| Security settings are missing | Your identity provider may manage them for an SSO account. |
| Sign-in remains blocked | Follow the displayed wait time and contact your administrator if needed. |
Related: Getting started · Settings