🔐 Security · Sign-in

A stolen password no longer opens the door

Every GSE-Web user can add a second lock to their account: a six-digit code shown on their phone. And for companies whose employees have a Microsoft account, enterprise sign-in (SSO) is available as an option.

Two-factor authentication

All plans

Trusted device

30 days

Enterprise SSO

Option, on quotation

Sign in to GSE-Web
Protected

6

digits in each code, renewed every 30 seconds

30

days without a code on a trusted device

0

GSE-Web passwords for your employees to remember, with SSO

1 min

at most to sign out a suspended account

In a nutshell

Two locks are better than one

The password is something you know; the phone is something you have. You need both to get in.

Enter, confirm, sign in.

1

The password

You sign in as usual, on the web or in the mobile app, with your username and password.

“A guessed password, or one reused on another site, stops here.”
2

The phone code

GSE-Web asks for the six-digit code shown at that moment by your authenticator app: Google Authenticator, Microsoft Authenticator, iPhone Passwords…

A new code every 30 seconds, even with no network on the phone
3

Sign in

The session opens. On your usual computer, tick “Trust this device for 30 days”: you will not be asked for the code there before that date.

Lost your phone? A single-use backup code takes its place.
💳

The bank card and its PIN

A bank card alone will not let you withdraw cash: you also need the PIN. And the PIN alone is useless without the card. Two-factor authentication applies the same rule to your GSE-Web account: whoever has found out your password does not have your phone.

Getting started

Turned on in two steps

Each user turns it on themselves, for their own account. Nothing to install, nothing to request.

1

Open “My information”

In the “Two-factor authentication” card, click “Enable” and confirm your password.

Menu › My information › Two-factor authentication › Enable
2

Scan the QR code, then enter the first code

Scan the QR code with the authenticator app on your phone, or type in the key shown next to it. Then enter the code the app displays: it is this first correct code that switches the protection on.

Keep your backup codes. They are shown when you enable the feature, can be copied in one click and each works only once. Store them somewhere other than your phone: they are what lets you in if you lose it.

Is it mandatory? No: within your organisation, each user chooses whether to turn it on. It is required only of GSE-Web platform administrators, and of the administrator who sets up enterprise sign-in.

Four situations, one door

Signing in in two steps

On the web and in the mobile app

Sign-in › Username and password › Two-factor authentication code › Confirm

After the password, a window asks for the six-digit code. On your usual device, the “Trust this device for 30 days” box saves you from typing it every time. Code rejected? Check the time on your phone: the code depends on it.

AI assistants you connect to GSE-Web go through the same door: two-factor authentication is requested when you authorise them.

Backup codes

Plan B if the phone is lost

Sign-in › Two-factor authentication code › Use a backup code

Instead of the app code, enter one of your backup codes: each one works only once. From “My information”, the “New backup codes” button generates a new set, after you confirm your password.

Turning two-factor authentication off also asks for the password: a session left open on a computer is not enough to remove the lock.

Enterprise sign-in (SSO)

Paid option · dedicated server

Sign-in › Enterprise SSO › company Microsoft account › GSE-Web

Your employees click “Enterprise SSO” and sign in with their Microsoft (Entra ID) account, with no GSE-Web password. Only addresses from the email domains you declare are accepted. On first sign-in, the account is created with the role you have chosen, never an administrator role.

Available today on the web; the mobile app is not yet covered. Set up on quotation, after a scoping session with your IT department.

Cutting off access

Someone leaves, a device goes missing, a doubt

ADMIN › Users › Edit user › Account access

Your organisation's administrator flips the “Account access” switch: the account is suspended, its sessions are closed and the open app is signed out within a minute. The account is not deleted: it can be reactivated at any time, with nothing lost.

Sign-in tokens expire after 24 hours and are renewed only while the session is open: a closed session does not live on.

Safeguards

What the software guarantees

Security does not depend on everyone staying alert: the rules are checked by the server, at every sign-in.

A badly scanned QR code locks nobody out

Protection is switched on only by the first correct code. As long as your app does not produce the right code, nothing changes for you: you sign in as before.

Password asked again for every change

Turning two-factor authentication on or off, generating new backup codes: each step requires your password. Someone walking past a computer left open cannot remove the lock.

Always a backup account

Enterprise sign-in cannot be switched on until there is an administrator with a password and two-factor authentication. If the company directory is unavailable, someone keeps control.

Access cut off within a minute

A suspended account is refused by the server, its sessions are closed and the open app is signed out at the next exchange. Its groups, permissions and history stay intact for the day it is reactivated.

Enterprise option

Enterprise sign-in (SSO)

For organisations whose employees already have a Microsoft account: the same identity, managed by your IT department, also opens GSE-Web.

What the option includes

Sign-in through your directory: OpenID Connect standard, proven with Microsoft Entra ID. Your directory's rules, such as its own multi-factor authentication, apply before anyone enters GSE-Web.

Matching by domain: only addresses from the email domains you declare are accepted, subdomains excluded. A guest from outside your directory is refused.

Accounts created on first sign-in, with the role chosen by your administrator, never an administrator role. An account that already existed keeps its groups, permissions and history. Each account counts towards the users of your subscription.

Mandatory SSO, if you wish: password sign-in is then refused for addresses in your domains, except for backup administrator accounts.

🏢

On a dedicated server, after scoping

The option is set up on the server dedicated to your organisation (CORPORATE plan), after a scoping session with your IT department, which receives a step-by-step procedure. It is subject to a quotation.

⏳

What is not covered yet

The mobile app, automatic account synchronisation from the directory, and the SAML protocol. Disabling an employee in the directory blocks their new sign-ins; to close a session that is already open, you suspend their account in GSE-Web.

Vocabulary

The words of sign-in security

Six terms you will meet on screen, explained without jargon.

Two-factor authentication

Two proofs instead of one to get in: something you know (the password) and something you have (the phone).

Authenticator app

A phone app that shows a new six-digit code every 30 seconds, even with no network.

Backup code

A single-use code, given when you enable the feature, that replaces the phone code if you no longer have the phone.

Trusted device

A computer or phone on which you ticked the box: the code is not asked for there for 30 days.

SSO (single sign-on)

Signing in to GSE-Web with your company account, without a password specific to the software.

Backup account

An administrator with a password and two-factor authentication, who keeps access even if the company directory is unavailable.

Roles

Who does what

Each user manages their own two-factor authentication; account access and enterprise sign-in are managed by the administrator.

Action What it allows
Every user
Two-factor authentication Turn it on or off and generate new backup codes, for their own account.
Your organisation's administrator
Account access Suspend or reactivate an account; on suspension, its sessions are closed.
Active sessions See which users are signed in and sign them out.
Enterprise sign-in (option)
Enterprise sign-in (SSO) Enter the directory details, allowed domains and the role for new accounts, switch on mandatory SSO. Requires two-factor authentication on their own account.
Opening the option Open the option on your server once subscribed. When closed, nothing is deleted: the configuration is kept.
Traceability

Every sign-in
leaves a trace

Sign-ins, refusals, suspensions, closed sessions: everything is recorded in the audit log, which cannot be altered, included from the ENTREPRISE plan.

Sign-ins and sign-outs, with the IP address, device and app used.

Two-factor authentication turned on, turned off, or code rejected.

Closed sessions, with their reason: account suspended, removed from the organisation, password reset or changed.

Enterprise sign-in: sign-ins through the directory, refusals with their reason, configuration changes.

Audit log — one suspension, two entries
// the administrator suspends the account
"action": "TENANTS_USER_SUSPENSION_UPDATED",
"occurredAt": "2026-10-09T08:42:17Z",
"details": { "suspended": true },

// the open session is closed straight away
"action": "AUTH_SESSION_REVOKED",
"details": { "reason": "user_suspended" },
"outcome": "success",

// same request: the two entries are linked
"requestId": "5f1c2a9e-3b7d-4e0a-9c61-2d8b7a4f0e13"

A second lock, effortlessly.
And your directory, if you wish.

Two-factor authentication is included in every plan. For enterprise sign-in, let's talk about your directory and your organisation: the quotation follows the scoping.

Frequently asked questions

Is two-factor authentication mandatory in GSE-Web?

No. Each user turns it on for their own account, from “My information”. It is required only of GSE-Web platform administrators, and of the administrator who sets up enterprise sign-in. It is included in every plan.

What if I lose my phone?

Sign in with one of your backup codes, each of which works only once, then turn two-factor authentication off and on again with your new phone. Without a backup code, contact KLS-Concept support.

Which authenticator apps work?

Any app that reads a standard authentication QR code (TOTP): Google Authenticator, Microsoft Authenticator or iPhone Passwords, for example. Without a camera, the key shown next to the QR code can be typed in by hand. The phone does not need a network to display the code.

Is enterprise sign-in (SSO) included in my plan?

No, it is a paid option, on quotation. It is set up on the server dedicated to your organisation (CORPORATE plan), after a scoping session with your IT department. It works today on the web, with Microsoft Entra ID; the mobile app is not yet covered.

When an employee leaves, how do I cut off their access?

The administrator suspends their account in GSE-Web (the “Account access” switch): the server refuses it immediately, its sessions are closed and the open app is signed out within a minute. With enterprise sign-in, disabling them in your directory prevents any new sign-in but does not close a session that is already open: suspending the account in GSE-Web remains the step to take.