Skip to main content

Security

The Security page is where you protect your Mumara ONE account: restrict the IP addresses it can be used from, see where it's signed in, and turn on two-factor authentication.

To open it, click your avatar in the top-right corner and choose Security. You can also reach it from the User Menu on the left of My Profile.

The page has four sections:

SectionWhat it's for
PasswordWhere to change your password
Allowed IP AddressesLimit sign-ins to addresses you trust
Active sessionsSee and end the sessions signed in to your account
Two-Factor AuthenticationAsk for a code from your phone at every sign-in

Password​

Your password belongs to your billing profile, the same as your name and email address. The Password section shows this note instead of a change-password button:

These settings are managed under your billing profile. Click here to navigate to the billing profile.

To change your password:

  1. Click Click here in the note. Your billing profile opens in a new tab, without signing in again.
  2. Change your password there and save it.

Your Mumara ONE sign-in changes to match. You can also open your billing profile from Quick Navigation → Account in the top bar.

If you've forgotten your password, click Forgot Password ? on the sign-in page at account.mumara.com. See Sign Up and Onboarding.

Choose a strong password

Use at least 12 characters, mix letters, numbers and symbols, and don't reuse a password from another site. A password manager makes this easy.

Allowed IP Addresses​

Restrict access by adding a range of trusted IP addresses. If no IP address is added, the account will be accessible from any IP address.

SettingResult
No addresses listedYour account can be used from any IP address. This is the default.
One or more addresses listedSign-ins are only allowed from the addresses you've listed.
Use static IP addresses only

Only add addresses that don't change, such as your office's fixed IP. Many home and mobile connections get a new address from time to time. If your address changes and isn't on the list, you can be locked out of your account.

Keep your account.mumara.com sign-in secure too

You sign in to Mumara ONE through account.mumara.com. Protect that sign-in as well: use a strong password that you don't use anywhere else, don't share it, and turn on two-factor authentication here.

Add an allowed IP address​

  1. Click Add IP Address.

  2. Choose one of the options:

    OptionWhat to enter
    Add your current IP addressNothing. The address you're using now is shown in brackets and added as it is.
    Add a static IP addressOne address, for example 203.0.113.10.
    Add a subnetA network in CIDR notation: the first address, then the prefix length, for example 203.0.113.0 / 24 for all 256 addresses from 203.0.113.0 to 203.0.113.255. The prefix length can be from 8 to 32.
    Add an IP rangeThe first address, then how many consecutive addresses to allow, for example 203.0.113.10 - 5 for 203.0.113.10 to 203.0.113.14. Each address is added to the list separately.
  3. Click Next. The dialog shows the address you entered under Your IP address.

  4. Enter an IP Label, a name that tells you what the address is, for example Office. It's required.

  5. Click Add.

The dialog reminds you that All future sign-ins will only be permitted from this IP range. Before you add the first address, make sure it includes the one you're using now.

Your allowed addresses​

Each entry shows its label, when it was added, the address or network, and its location. The first few entries appear on the page. Click View more to see them all.

If you have allowed addresses and the one you're using now isn't among them, a Note warns you that you won't be able to sign in again from this address once you sign out. Click Add next to it to add your current address.

Remove an allowed IP address​

  1. Click Remove next to the entry.
  2. Check the details and click Remove in the dialog.

When you remove the last entry, your account can be used from any IP address again.

Active sessions​

This section lists the devices where your account is signed in right now. Its heading reads View and manage all of your active sessions.

Each session shows:

  • the operating system of the device, and how long ago the session started
  • the IP address it connected from
  • icons for the operating system and browser
  • the location, based on the IP address
  • Current Session for the device you're using now, or Terminate for any other

Click a session to see its details: Session started on, IP Address, Operating System, Browser and Location. When you have more than a few sessions, click View more to open the full Active Sessions list.

End a session​

To sign out a device you don't use any more, or don't recognize:

  1. Find the session, clicking View more if needed.
  2. Click Terminate on the session. A dialog opens with the session's details.
  3. Check the details and click Terminate in the dialog.

That device is signed out and has to sign in again. You can't terminate the session you're using now: to end it, click Logout in the user menu.

A session you don't recognize

Terminate it straight away, then change your password in your billing profile and turn on two-factor authentication. Check Activity Logs for changes you didn't make.

Two-Factor Authentication​

Every time you sign in, you'll need both your password and a time-based authentication token.

With two-factor authentication on, signing in takes your password and a 6-digit code from an authenticator app on your phone, such as Google Authenticator, Microsoft Authenticator or Authy. Someone who learns your password still can't get in without your phone.

Turn on two-factor authentication​

  1. Install an authenticator app on your phone, if you don't have one.
  2. On the Security page, switch on Enable/Disable in the Two-Factor Authentication section. The Enable Two-Factor Authentication dialog opens, with three steps: Setup, Scan and Verify.
  3. Setup: read the explanation under Secure Your Account and click Get Started.
  4. Scan: in your authenticator app, add a new account, then scan the QR code. If you can't scan it, type the Manual Entry Key into the app instead; spaces don't matter. Click Confirm.
  5. Verify: enter the 6-digit code your app shows now and click Confirm.
  6. The dialog shows Two-factor authentication setup is complete! and Your backup code is: followed by a 16-character code. Click Copy and store the code somewhere safe, then close the dialog.
Save your backup code now

The backup code is your way in if you lose your phone or delete the authenticator app. It's shown only once. Keep it in a password manager or another safe place, not on the same phone.

Sign in with two-factor authentication​

After you sign in at account.mumara.com, the app asks for your code when you arrive:

  1. Open your authenticator app and find the Mumara ONE entry.
  2. Enter the current 6-digit code in the Authentication Code field and click Login.

Codes change every 30 seconds. If one is rejected, wait for the next code and try again.

Sign in with your backup code​

If you can't use your phone:

  1. On the code screen, click Can't access your 2FA device? Use a backup code to log in.
  2. Enter your backup code in the Backup Code field and click Login.
  3. A backup code works only once, so the screen shows Your new one-time backup code is: with a replacement. Save the new code in place of the old one, then click Continue.

If you've lost both your phone and your backup code, contact Mumara ONE support.

Turn off two-factor authentication​

  1. Switch off Enable/Disable in the Two-Factor Authentication section.
  2. In the Disable Two-Factor Authentication dialog, enter your password, the one you use at account.mumara.com.
  3. Click Disable.

From then on, you sign in with your password only.

Moving to a new phone

Turn two-factor authentication off, then turn it on again and scan the new QR code with the app on your new phone. Save the new backup code you're given.

Good practice​

  • Turn on two-factor authentication. It's the best protection against a stolen password.
  • Save your backup code as soon as you're given it, and replace it whenever you get a new one.
  • Check your active sessions from time to time, and terminate any you don't recognize or no longer use.
  • Only allow static IP addresses, and add more than one trusted location if you work from several places.

Troubleshooting​

My two-factor code isn't accepted​

  • Make sure your phone's clock is set automatically. Codes depend on the exact time.
  • Check that you're reading the Mumara ONE entry in your authenticator app, not another account's.
  • Wait for a new code and enter it straight away.
  • Use your backup code instead. See Sign in with your backup code.

I've lost access to my authenticator app​

Sign in with your backup code, turn two-factor authentication off and on again, and scan the QR code with your new app. If you don't have your backup code either, contact Mumara ONE support.

I'm locked out by an IP restriction​

Sign in from one of your allowed addresses and add your new address, or remove the restriction. If you can't reach any of them, contact Mumara ONE support.

I can't change my password on this page​

Your password is managed in your billing profile. Click Click here in the Password section, or use Quick Navigation → Account.

Next steps​