A stolen password no longer opens the door
Every GSE-Web user can add a second lock to their account: a six-digit code shown on their phone. And for companies whose employees have a Microsoft account, enterprise sign-in (SSO) is available as an option.
Two-factor authentication
All plans
Trusted device
30 days
Enterprise SSO
Option, on quotation
6
digits in each code, renewed every 30 seconds
30
days without a code on a trusted device
0
GSE-Web passwords for your employees to remember, with SSO
1 min
at most to sign out a suspended account
Two locks are better than one
The password is something you know; the phone is something you have. You need both to get in.
Enter, confirm, sign in.
The password
You sign in as usual, on the web or in the mobile app, with your username and password.
The phone code
GSE-Web asks for the six-digit code shown at that moment by your authenticator app: Google Authenticator, Microsoft Authenticator, iPhone Passwords…
Sign in
The session opens. On your usual computer, tick “Trust this device for 30 days”: you will not be asked for the code there before that date.
The bank card and its PIN
A bank card alone will not let you withdraw cash: you also need the PIN. And the PIN alone is useless without the card. Two-factor authentication applies the same rule to your GSE-Web account: whoever has found out your password does not have your phone.
Turned on in two steps
Each user turns it on themselves, for their own account. Nothing to install, nothing to request.
Open “My information”
In the “Two-factor authentication” card, click “Enable” and confirm your password.
Scan the QR code, then enter the first code
Scan the QR code with the authenticator app on your phone, or type in the key shown next to it. Then enter the code the app displays: it is this first correct code that switches the protection on.
Keep your backup codes. They are shown when you enable the feature, can be copied in one click and each works only once. Store them somewhere other than your phone: they are what lets you in if you lose it.
Is it mandatory? No: within your organisation, each user chooses whether to turn it on. It is required only of GSE-Web platform administrators, and of the administrator who sets up enterprise sign-in.
Four situations, one door
Signing in in two steps
On the web and in the mobile app
After the password, a window asks for the six-digit code. On your usual device, the “Trust this device for 30 days” box saves you from typing it every time. Code rejected? Check the time on your phone: the code depends on it.
AI assistants you connect to GSE-Web go through the same door: two-factor authentication is requested when you authorise them.
Backup codes
Plan B if the phone is lost
Instead of the app code, enter one of your backup codes: each one works only once. From “My information”, the “New backup codes” button generates a new set, after you confirm your password.
Turning two-factor authentication off also asks for the password: a session left open on a computer is not enough to remove the lock.
Enterprise sign-in (SSO)
Paid option · dedicated server
Your employees click “Enterprise SSO” and sign in with their Microsoft (Entra ID) account, with no GSE-Web password. Only addresses from the email domains you declare are accepted. On first sign-in, the account is created with the role you have chosen, never an administrator role.
Available today on the web; the mobile app is not yet covered. Set up on quotation, after a scoping session with your IT department.
Cutting off access
Someone leaves, a device goes missing, a doubt
Your organisation's administrator flips the “Account access” switch: the account is suspended, its sessions are closed and the open app is signed out within a minute. The account is not deleted: it can be reactivated at any time, with nothing lost.
Sign-in tokens expire after 24 hours and are renewed only while the session is open: a closed session does not live on.
What the software guarantees
Security does not depend on everyone staying alert: the rules are checked by the server, at every sign-in.
A badly scanned QR code locks nobody out
Protection is switched on only by the first correct code. As long as your app does not produce the right code, nothing changes for you: you sign in as before.
Password asked again for every change
Turning two-factor authentication on or off, generating new backup codes: each step requires your password. Someone walking past a computer left open cannot remove the lock.
Always a backup account
Enterprise sign-in cannot be switched on until there is an administrator with a password and two-factor authentication. If the company directory is unavailable, someone keeps control.
Access cut off within a minute
A suspended account is refused by the server, its sessions are closed and the open app is signed out at the next exchange. Its groups, permissions and history stay intact for the day it is reactivated.
Enterprise sign-in (SSO)
For organisations whose employees already have a Microsoft account: the same identity, managed by your IT department, also opens GSE-Web.
What the option includes
Sign-in through your directory: OpenID Connect standard, proven with Microsoft Entra ID. Your directory's rules, such as its own multi-factor authentication, apply before anyone enters GSE-Web.
Matching by domain: only addresses from the email domains you declare are accepted, subdomains excluded. A guest from outside your directory is refused.
Accounts created on first sign-in, with the role chosen by your administrator, never an administrator role. An account that already existed keeps its groups, permissions and history. Each account counts towards the users of your subscription.
Mandatory SSO, if you wish: password sign-in is then refused for addresses in your domains, except for backup administrator accounts.
On a dedicated server, after scoping
The option is set up on the server dedicated to your organisation (CORPORATE plan), after a scoping session with your IT department, which receives a step-by-step procedure. It is subject to a quotation.
What is not covered yet
The mobile app, automatic account synchronisation from the directory, and the SAML protocol. Disabling an employee in the directory blocks their new sign-ins; to close a session that is already open, you suspend their account in GSE-Web.
The words of sign-in security
Six terms you will meet on screen, explained without jargon.
Two-factor authentication
Two proofs instead of one to get in: something you know (the password) and something you have (the phone).
Authenticator app
A phone app that shows a new six-digit code every 30 seconds, even with no network.
Backup code
A single-use code, given when you enable the feature, that replaces the phone code if you no longer have the phone.
Trusted device
A computer or phone on which you ticked the box: the code is not asked for there for 30 days.
SSO (single sign-on)
Signing in to GSE-Web with your company account, without a password specific to the software.
Backup account
An administrator with a password and two-factor authentication, who keeps access even if the company directory is unavailable.
Who does what
Each user manages their own two-factor authentication; account access and enterprise sign-in are managed by the administrator.
| Action | What it allows | |
|---|---|---|
| Every user | ||
| Two-factor authentication | Turn it on or off and generate new backup codes, for their own account. | |
| Your organisation's administrator | ||
| Account access | Suspend or reactivate an account; on suspension, its sessions are closed. | |
| Active sessions | See which users are signed in and sign them out. | |
| Enterprise sign-in (option) | ||
| Enterprise sign-in (SSO) | Enter the directory details, allowed domains and the role for new accounts, switch on mandatory SSO. Requires two-factor authentication on their own account. | |
| Opening the option | Open the option on your server once subscribed. When closed, nothing is deleted: the configuration is kept. | |
Every sign-in
leaves a trace
Sign-ins, refusals, suspensions, closed sessions: everything is recorded in the audit log, which cannot be altered, included from the ENTREPRISE plan.
Sign-ins and sign-outs, with the IP address, device and app used.
Two-factor authentication turned on, turned off, or code rejected.
Closed sessions, with their reason: account suspended, removed from the organisation, password reset or changed.
Enterprise sign-in: sign-ins through the directory, refusals with their reason, configuration changes.
"action": "TENANTS_USER_SUSPENSION_UPDATED",
"occurredAt": "2026-10-09T08:42:17Z",
"details": { "suspended": true },
// the open session is closed straight away
"action": "AUTH_SESSION_REVOKED",
"details": { "reason": "user_suspended" },
"outcome": "success",
// same request: the two entries are linked
"requestId": "5f1c2a9e-3b7d-4e0a-9c61-2d8b7a4f0e13"
A second lock, effortlessly.
And your directory, if you wish.
Two-factor authentication is included in every plan. For enterprise sign-in, let's talk about your directory and your organisation: the quotation follows the scoping.
Frequently asked questions
Is two-factor authentication mandatory in GSE-Web?
No. Each user turns it on for their own account, from “My information”. It is required only of GSE-Web platform administrators, and of the administrator who sets up enterprise sign-in. It is included in every plan.
What if I lose my phone?
Sign in with one of your backup codes, each of which works only once, then turn two-factor authentication off and on again with your new phone. Without a backup code, contact KLS-Concept support.
Which authenticator apps work?
Any app that reads a standard authentication QR code (TOTP): Google Authenticator, Microsoft Authenticator or iPhone Passwords, for example. Without a camera, the key shown next to the QR code can be typed in by hand. The phone does not need a network to display the code.
Is enterprise sign-in (SSO) included in my plan?
No, it is a paid option, on quotation. It is set up on the server dedicated to your organisation (CORPORATE plan), after a scoping session with your IT department. It works today on the web, with Microsoft Entra ID; the mobile app is not yet covered.
When an employee leaves, how do I cut off their access?
The administrator suspends their account in GSE-Web (the “Account access” switch): the server refuses it immediately, its sessions are closed and the open app is signed out within a minute. With enterprise sign-in, disabling them in your directory prevents any new sign-in but does not close a session that is already open: suspending the account in GSE-Web remains the step to take.