Salta al contenuto principale

Practical guide

Two-factor authentication in condominium software

Two-factor authentication, often shortened to 2FA, is a login method that requires two different proofs to confirm the identity of whoever accesses the software: something you know, that is the password, and something you have, usually a temporary code generated by an app or received on your phone. For a condominium manager, who handles owners' registries, budgets and tax documents as a data controller under the GDPR, 2FA is one of the most effective and low-cost technical measures to reduce the risk of unauthorised access, even when the password is stolen or guessed.

Why the password alone is no longer enough

Passwords are compromised every day for predictable reasons: they are too simple, they are reused across several services, they end up in leaked lists after breaches on other sites, or they are captured through deceptive messages. When a manager's or a staff member's password is stolen, whoever holds it can enter the software and view the data of every condominium managed, often without anyone noticing right away.

Two-factor authentication breaks this mechanism. Even someone who knew the password could not complete the login without the second factor, which stays physically on the legitimate owner's device. This is why Article 32 of the GDPR calls for technical measures appropriate to the risk: 2FA is among the most concrete and proportionate for a management practice.

How the second factor works in practice

In the most common model, after entering email and password the software asks for a six-digit numeric code that changes every few seconds. This code is generated by an authenticator app installed on the smartphone, which does not need an internet connection to work. Alternatively the code can arrive by SMS, a more convenient but slightly less secure option because the message travels over the mobile network.

There are also stronger factors, such as physical security keys or the device's biometric recognition. For a condominium management practice, the authenticator app usually offers the best balance of security, zero cost and ease of use, because it does not depend on mobile coverage and requires no extra hardware.

Who should enable it: manager, staff and owners

The absolute priority is protecting the accounts with the greatest privileges: the managing controller and the practice's staff, who access the data of several condominiums and can modify budgets, cost allocations and registries. On these profiles 2FA should be mandatory, not optional, because the compromise of a single one exposes the entire portfolio of buildings managed.

The individual owners' private area also deserves attention. Although each owner sees only their own data, that data remains personal and financial information. Offering 2FA to owners too, at least as an option, is consistent with the GDPR accountability principle and strengthens trust in the service the manager provides.

Recovery codes and what to do if you lose your phone

The most common fear about 2FA is being locked out of your own account. That is why a well-designed software provides, at activation, a set of single-use recovery codes to keep in a safe place, such as a digital vault or a protected practice archive. These codes allow you to get back in even if the device is lost or replaced.

It is good practice to regenerate recovery codes if you suspect they have been exposed and, where possible, to configure more than one second-factor method. In a practice with several staff members, it helps to define an internal procedure setting out who can reset an account's 2FA and with what checks, so that the feature does not itself become a way in.

Enabling 2FA without slowing down daily work

A software like AmministraPro integrates two-factor authentication together with role-based access profiling, so the manager can raise the level of protection without burdening daily work. Anyone who wants to understand how access security is organised can review the capabilities on the features page and compare the plans on the pricing page.

  • Start with manager and staff accounts before extending it to owners.
  • Prefer an authenticator app over SMS when both options are available.
  • Store recovery codes in a secure archive, not in a personal email inbox.
  • Allow trusted devices, so the code is not requested at every login from the same office computer.
  • Record the activation of 2FA among the security measures in the record of processing activities.
  • Periodically check that all active staff members have the second factor configured.

Frequently asked questions

Is two-factor authentication legally mandatory for a condominium manager?

There is no rule that expressly requires 2FA for condominium managers. Article 32 of the GDPR does, however, require technical measures appropriate to the risk of the processing. Since the manager handles personal and financial data of many owners, two-factor authentication is a proportionate measure that is easily justified from an accountability standpoint.

Does 2FA slow down daily access to the software?

Only marginally. Many products let you mark the practice's usual devices as trusted, so the second factor is requested only periodically or from new workstations. Access from a new computer or an unrecognised network does require the code, and those are exactly the cases where the protection matters most.

What happens if a staff member loses the phone with the authenticator app?

If single-use recovery codes were saved at activation, the staff member uses them to get back in and configure a new device. Without codes, whoever manages accounts in the practice must step in, following an identity verification procedure so that the reset does not itself become a weak point.

Is SMS a secure second factor?

SMS is better than the password alone, but it is considered less secure than an authenticator app, because the message can be intercepted or diverted through SIM-swapping techniques. When the software offers both options, an authenticator app is preferable for high-privilege accounts, keeping SMS as a backup method.

Should owners enable 2FA on their private area too?

It is advisable to offer it at least as an option. Each owner sees only their own data, but this is still personal and accounting information. Making two-factor authentication available on the private area strengthens protection and shows owners the manager's attention to the security of their data.

Try AmministraPro

Accounting, thousandths-based cost splitting, meetings, communications and artificial intelligence in a single Italian software, compliant with UNI 10801 and GDPR.