Email as a multi-factor authentication method
Not everyone has access too or wants to use an authenticator app. I would like to have a code send to my mobile or email as the authentication method. When we setup Xero asks for a backup email address which codes can be sent too. So if codes can easily be sent to a backup email address, then why cant they just go to the users email address ? Please consider allowing code to be emailed to the user as multi-factor authentication method, instead of only allowing an email to a backup email address.
We appreciate your feedback about Multi-factor authentication. (MFA) is mandatory for Xero customers with access to a paying organisation. It’s critical to help protect your sensitive data from security breaches and account compromises globally. We take security seriously and protecting our customers' data is our highest priority. Cyber attackers and hackers are only getting more sophisticated and by implementing MFA, you're adding a second layer of security to your account. Thank you for sharing this with us. I'll make sure your ideas get in front of the right team for review. While we aren't able to commit to changing this right now, your feedback is incredibly helpful as we plan future improvements