Limited time only. 90% off QuickBooks for 6 months.
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements
vin0x00a2
Returning Member

Buggy MFA and Authentication Flow on Quickbooks Online and Intuit

I've noticed a couple technical bugs, related to the overall mfa authentication flow, when using QuickBooks Online.

 

It seems there have been some changes pushed recently but they are a bit buggy and not unified.

 

I've selected "2fa authenticator app" to be my primary second factor verification method:

 

Issue 1:

I don't get that option to verify my identity when updating account managers.

Issue 2:

When I sign in, I only get the authenticator app for 2fa if I use the email and password option. If I request a code to be texted I get an email code for my 2fa instead of the authenticator app, which isn't even an option I can select in the 2-step verification page.

As a user because I've selected authenticator app as my primary 2fa I expect that to be consistent across all mfa requests. 

 

Wondering what's the best place I can report these bugs, and a few others, and provide some further feedback for improvement?

 

To me it seems like verification, MFA, 2-step etc are not unified between Intuit and Quickbooks. I'm getting the sense that these are being handled differently, depending on how the flow was started, and If I am honest it's really causing me doubt about whether the auth and mfa methods have been implemented correctly to begin with, and it seems like a sort of by-pass of the selected 2fa methods depending on which flow was taken. 

 

I use QuickBooks a lot and it contains important and sensitive data for myself, employees, and my company and I want to be confident in the systems I am trusting with this data.

 

My company consults in Development, Operations, and Security, so I am aware of the time, effort, and requirements it takes to improve these types of systems. 

Please let me know how I can best provide this additional feed back and share any other details needed.

3 Comments 3
EduardA
QuickBooks Team

Buggy MFA and Authentication Flow on Quickbooks Online and Intuit

Welcome to the Community, @vin0x00a2.

 

You may want to refresh the connection between your authenticator app and QuickBooks Online (QBO) by removing the app from your Intuit Account and then adding it again.

 

Here's how:

 

  1. Go to your QBO account profile, then select Manage your Intuit Account.
  2. Navigate to Sign in & security.
  3. Remove your authenticator app from the Authenticator section, then add it back.

 

For more reminders about authentication and security, check out these articles:

 

 

Should you have any further questions, feel free to reply to this thread.

vin0x00a2
Returning Member

Buggy MFA and Authentication Flow on Quickbooks Online and Intuit

@EduardA 

 

The issue is not the authenticator app and qbo. When I use email and password method I am prompted for the 2fa via the authenticator app.

 

However when I sign in via phone number, I am not prompted for 2fa via the preferred method rather I am sent an email code as the second step. I would expect at this stage to be prompted for 2fa via the preferred method, however an email code is sent. Email is not even a method I can specify for 2fa on the security preferences page. 

 

If I sign in with my phone I can essentially bypass the preferred 2fa method because it sends an email, then even prompts to change the password, and set up a passkey. All without doing the preferred 2fa method that I have setup. 

BonJulius_G
QuickBooks Team

Buggy MFA and Authentication Flow on Quickbooks Online and Intuit

Hi, vin0x00a2.


Thank you for sharing your concerns and observations about the Multi-Factor Authentication (MFA) and authentication flow in QuickBooks Online (QBO). I understand how inconsistencies in the authentication process across different methods can raise valid concerns about security and reliability.

 

For personalized assistance, I recommend contacting our live support team to review your account setup and two-factor authentication (2FA) settings. They can help investigate the issue and address any misconfigurations specific to your account.

 

Here’s how:

 

  1. Navigate to the Help menu.
  2. Click the Search option and type "contact support."
  3. Click the Contact Us tab at the bottom.
  4. Enter the question, keyword, or topic for which you need assistance.
  5. Follow the prompts, then select your preferred way to connect with us: Have us call you or Chat with us.

 

If you’d like to report these bugs and provide feedback for improvement, you can send your suggestions directly to our product developers.

 

Let us know if you have any further questions. We’re here to assist you.

Need to get in touch?

Contact us