Sign in with any method available for your FTE Tree account unless the organization requires its company sign-in method. Depending on the organization and the action, you may also need to complete FTE Tree multi-factor authentication (MFA).

FTE Tree MFA uses a compatible authenticator app or a saved recovery code and remains separate from MFA required by Microsoft, Google, or your company sign-in provider. Each organization sets its standard access requirement, while protected account and administrative changes can still require a recent FTE Tree MFA check.

Sign in

  1. Open the FTE Tree sign-in page. If your organization requires company sign-in, open the organization-specific Company sign-in URL provided by your organization administrator instead.
  2. Otherwise, choose your password, Microsoft, Google, or email code method.
  3. Complete MFA if prompted.
  4. Choose an organization when your account belongs to more than one.

Use the method required by the organization. A matching email domain alone does not satisfy a company sign-in requirement.

Microsoft, Google, and company sign-in first authenticate you through that provider. Provider MFA remains separate from FTE Tree MFA. FTE Tree may still ask for a code from your authenticator app or a recovery code for organization entry, account confirmation, or a protected administrative change.

Organization MFA choices

People with the Manage sign-in security permission can choose one of these policies for each organization:

  • Authenticator app optional for standard access adds no FTE Tree MFA check for ordinary entry. Microsoft, Google, or a company sign-in service may still require its own MFA. Protected administrative and account changes still use their separate FTE Tree checks.
  • Require an authenticator app for standard access requires a current code from a compatible authenticator app, or a recovery code, before organization entry.

Company sign-in is a separate organization requirement. If company sign-in and FTE Tree MFA are both required, you must complete both. An authenticator app does not replace required company sign-in, and provider MFA does not replace FTE Tree MFA.

Switching organizations can introduce a different company sign-in or FTE Tree MFA requirement, even in the same browser session.

Sign in with an email code

  1. Select Send a sign-in code.
  2. Enter the verified email for your account.
  3. Open the email and find the code.
  4. Enter it within 5 minutes.

If it expires, request a new code. Never send the code to another person or to Support.

If your normal sign-in method is unavailable

Use Recover account access when you have forgotten an FTE Tree password, lost the authenticator, exhausted your recovery codes, or cannot use an external sign-in provider. That guide identifies who owns each recovery step and what to do afterward.

An FTE Tree password reset does not change a Microsoft, Google, or company-account password. Recover an external password or MFA method through that provider or your company identity administrator.

Set up MFA

FTE Tree supports one compatible time-based one-time password (TOTP) authenticator app setup per account. You can use the authenticator app of your choice if it supports standard TOTP codes. Recovery codes are the backup FTE Tree MFA method.

FTE Tree does not currently support passkeys, hardware security keys, text-message codes, or email sign-in codes as FTE Tree MFA methods. Microsoft, Google, or a company sign-in provider may apply its own MFA separately.

Protected FTE Tree administration requires a code from your authenticator app or a recovery code. Provider MFA, an email sign-in code, and a trusted-browser choice do not satisfy the protected-action check. If you sign in only with Microsoft, Google, or a company provider and have not set up FTE Tree MFA, you must set up an authenticator app before continuing a protected organization or account change.

  1. Open Profile > Two-factor.
  2. Choose the authenticator setup option.
  3. Follow the setup instructions.
  4. Complete the verification.
  5. Save the recovery codes in a secure location separate from the device.

FTE Tree displays a generated set of recovery codes only once, and each code can be used once. Save the full set before leaving the page. Generating a new set replaces the existing set, so every code from the earlier set stops working.

Actions that require recent MFA

FTE Tree asks for recent MFA when you submit these organization administration changes or open a secure billing handoff:

Action Required MFA timing
Create, update, remind, or cancel an invitation; update or deactivate a membership Within the previous 24 hours in the current session
Create or change an access role, its permissions, role assignments, saved department access, availability, or whether it is active Within the previous 24 hours in the current session
Change allowed invitation and email recipient domains Within the previous 24 hours in the current session
Create or resume a paid subscription, cancel a trial, or open Stripe to manage or cancel a paid subscription Within the previous 24 hours in the current session
Change the organization’s FTE Tree MFA requirement Within the previous 15 minutes

Imports, reports, and ordinary workforce or setup changes use the normal sign-in and permission checks. They do not add one of these administrative MFA prompts. Personal account changes use the separate confirmation checks described in Manage your account.

How long a check lasts

For most protected access administration, email-domain changes, and billing actions, a successful MFA check is accepted within the previous 24 hours in the current session. Organization MFA-policy changes require a check within the previous 15 minutes.

Your session can still end after one hour of inactivity, when the browser closes, when you sign out, or when FTE Tree ends it for security reasons. The MFA window does not keep you signed in.

A trusted browser can reduce sign-in prompts but does not replace the recent MFA check for protected administrative work.

Continue a protected action

When a form requires MFA:

  1. Submit the reviewed form.
  2. Complete MFA when prompted.
  3. Return to the form, review your changes, and reattach any files.
  4. Submit the form again, then confirm the expected result.

Completing MFA does not submit your change. FTE Tree checks your current access when you submit the form again. You may need to enter your changes again after verification.

If you are prompted again for every form during the same active session, note the page, action, and approximate time, then contact us without sharing any secret codes.

Recovery codes and lost devices

Use a saved recovery code when your normal authenticator is unavailable. After signing in, replace the lost method and generate a new set of recovery codes.

If you lost both the authenticator and recovery codes, follow Recover account access and contact FTE Tree through the public support form. An organization administrator cannot request another person’s password or MFA reset from an organization page. MFA owned by Microsoft, Google, or another company provider must be recovered through that provider.

Security habits

  • Use a unique password.
  • Enable MFA before you urgently need it.
  • Keep recovery codes offline and private.
  • Review account sessions and sign out every other session if you do not recognize one.
  • Keep the account email current and verified.
  • Never share passwords, sign-in codes, authenticator codes, or recovery codes.

Why did my protected form expire?

The return link after verification lasts five minutes. If it expires, open the form again, review your changes, and submit it.