12 results found
-
MFA - Move cursor to code field automatically
When I login to Xero, I enter my email address and password and am taken to the second page (MFA).
I'm then asked for the authenticator code, but I have to click into the field to enter the code.
Xero knows that there is an almost 100% likelihood that the first (and only) thing I am going to do on that page is enter the MFA code.
Xero should automatically have the cursor in that field so that I can type the code without clicking into the field.
42 votesHi 👋 your idea is being looked into by our Community team. We will be in touch soon to update you once your idea has been reviewed.
-
pdf security
Please enhance security for all PDFs produced by Xero to prevent editing and stop potential fraud and theft.
Xero should have a setting to password protect the PDF from editing, which the administrator can control.
This should be a default setting that can be changed.1 voteHi 👋 your idea is being looked into by our Community team. We will be in touch soon to update you once your idea has been reviewed.
-
MFA | Role that can enable another user to reset multi factor authentication
Have a designated advisor / subscriber have the ability to remove multi factor authentication from a user so that a new method can be set up by the user.
Purpose: For those businesses that have operators which are not tech savy, having either the subscriber or the advisor who holds a professional membership / qualification, who have passed ID verification processes, let the designated person have the ability to toggle off multi factor authentication so that the user and re set up their authentication process so that when their phone is lost or stolen and their alternative entry points don't…
15 votesHi 👋 your idea is being looked into by our Community team. We will be in touch soon to update you once your idea has been reviewed.
-
History & Notes - Login - Timestamps for login history
Audit trail of logins to Xero - there seems to be a series of different visual aids and short screen reports showing when a user last logged in, however from an audit perspective, it would be ideal to have a report that can be run for set periods showing when users have logged in. The information to run this type of report is there from the History and Notes report and the Assurance Dashboard. However a report that shows a time/date stamp would be ideal as evidence in cases of fraud/performance management
21 votesHi 👋 your idea is being looked into by our Community team. We will be in touch soon to update you once your idea has been reviewed.
-
Login - Single Sign-on (SSO) across Xero Products
Would be nice when moving from Xero to Xero HQ and Xero Central to have it retain your login so you do not have to login to each site separately.
43 votesHi 👋 your idea is being looked into by our Community team. We will be in touch soon to update you once your idea has been reviewed.
-
MFA - Set up additional options
It would be really helpful to have more MFA options active - to be able to have the option of authenticator, back up email and security questions all active at the same time.
1 voteHi 👋 your idea is being looked into by our Community team. We will be in touch soon to update you once your idea has been reviewed.
-
Login page - Redirect to ReturnUrl if already logged in
Redirect to the ReturnUrl on the login page if you refresh and have already logged back in, eg. from another tab.
Context: I usually have many Xero tabs open. If I am logged out due to session timeout, all of these tabs redirect to the login page with a ReturnUrl in the query string. If I log in on one of those login pages, I am correctly returned to where I was in that tab. If I refresh another one of the tabs after logging in, it stays on the login page rather than automatically redirecting to the ReturnUrl.
It…
2 votesHi 👋 your idea is being looked into by our Community team. We will be in touch soon to update you once your idea has been reviewed.
-
Multi-Factor Authentication: Support for third party push notifications
With the recent changes to MFA dropping the remember devices from 30 days to 24 hours, the MFA prompt is now far more often (which is of course more secure) however it does slow down login.
Could you please look at updating the MFA configuration to allow push notifications to the mobile authentication app, or better still the number match, which is far more secure. Examples from Microsoft is below, but the priciple would apply in most major platforms.
https://learn.microsoft.com/en-us/azure/active-directory/authentication/how-to-mfa-number-match
This would improve the user experiance over the token, but also improve the security overall.
Thanks
Dave29 votesHi 👋 your idea is being looked into by our Community team. We will be in touch soon to update you once your idea has been reviewed.
-
Xero Accounting app - Password Confirmation
The mobile app currently does not ask you to confirm your password when you setup a pin for your account. If you were to miss-enter your pin, which is easy to do, you essentially immediately lock yourself out of your account. The system should ask for a pin, then ask you to confirm the pin before finalising it, allowing you to go back a step if you enter in the wrong pin.
2 votesHi 👋 your idea is being looked into by our Community team. We will be in touch soon to update you once your idea has been reviewed.
-
MFA - Allow setup of Multi-Factor Authentication on first Login
Currently, when you invite a brand new user to Xero who has never used Xero before:
1) on first log in you need to register for Xero & set password
2) on second log in, it asks you to set up multi-factor authentication (MFA)It would be great if MFA could all be set up in the first log in as it creates confusion for the new user on the second log in. Its also easier for accountants when helping clients to set up new log ins if it could all be done at once, rather than Register > log…
2 votesHi 👋 your idea is being looked into by our Community team. We will be in touch soon to update you once your idea has been reviewed.
-
MFA: Remember 'Trust this device' setting after 24 hours
I understand the ATO requires you to enter 2FA daily, but that doesn't mean the tickbox should uncheck itself every day.
If I tick trust this device on Monday and login using 2FA, I can then login without 2FA for 24 hours.
After that 24 hours, I need to login using 2FA again AND I have to tick the trust this device box again to get another 24 hour reprieve.
Let us tick the box or another box that will remember our choice ongoing. So each day I only have to login using 2FA again but my choice to trust…
11 votesHi 👋 your idea is being looked into by our Community team. We will be in touch soon to update you once your idea has been reviewed.
-
MFA - Option to switch between devices in Xero Verify
Changing MFA devices for Xero Verify brings over your accounts but on the Xero Identity Account page, when you attempt to change the device it makes you re-set up the account / code in Xero Verify. Would love to just have a 'change linked device' with a drop down of devices that have Verify attached to the account.
1 voteHi 👋 your idea is being looked into by our Community team. We will be in touch soon to update you once your idea has been reviewed.
- Don't see your idea?