(807) 700-7111 Free Assessment

Two-Factor Authentication (2FA)

Protect your phone system from toll fraud and unauthorized access by enabling two-factor authentication on every 3CX account.

Why 2FA Matters for Your Phone System

Toll fraud is one of the most expensive security risks for VoIP systems. Attackers who gain access to a 3CX account can make thousands of dollars worth of long-distance and international calls in a single weekend. Credential-stuffing attacks — where stolen passwords from other breaches are tried against your 3CX login — are increasingly common. Two-factor authentication adds a second layer of verification that stops these attacks even if a password is compromised.

Supported Authenticator Apps

3CX supports any TOTP-compatible authenticator app. The most common options are:

  • Google Authenticator — available on iOS and Android. Simple, no account required.
  • Microsoft Authenticator — integrates with Microsoft 365 accounts if your team already uses it.
  • Authy — supports cloud backup of tokens, making it easier to recover if you lose your phone.

How to Set Up 2FA

  1. Log in to the 3CX Web Client with your username and password.
  2. Click your profile icon or name in the top-right corner and select Profile Settings.
  3. Locate the Two-Factor Authentication section and click Enable.
  4. A QR code will appear on screen. Open your authenticator app on your phone and scan the QR code.
  5. The app will display a 6-digit code that refreshes every 30 seconds. Enter the current code into the 3CX confirmation field.
  6. Click Verify and then Save. 2FA is now active on your account.

From this point on, every login will require your password plus the current 6-digit code from your authenticator app.

Enforcing 2FA for All Users (Admins)

Administrators can require 2FA for every user on the system from the 3CX Management Console. Navigate to Security Settings and enable the option to enforce two-factor authentication. Once enabled, users who have not yet set up 2FA will be prompted to do so at their next login. DVGVoIP strongly recommends enforcing 2FA across your entire organization — a single unprotected account is enough for an attacker to cause significant damage.

After enforcing 2FA, give your team a few days' notice and share this guide so they can set up their authenticator app before the requirement takes effect.

Lost Your Authenticator?

If an employee loses their phone or deletes their authenticator app, they will be locked out of 3CX until their 2FA is reset. An administrator can reset 2FA for any user from the Management Console — the user will then be prompted to set up a new authenticator on their next login. If you do not have admin access, contact DVGVoIP support and we will assist with the reset.

Using Authy with cloud backup enabled can prevent lockouts — tokens are synced to a new device automatically. Google Authenticator requires manual re-enrollment if the phone is lost.

Installing the 3CX PWA (Progressive Web App)

The 3CX desktop app for Mac has been discontinued. The recommended replacement is the Progressive Web App (PWA), which runs in Chrome or Edge and provides the same functionality — including desktop notifications, click-to-call, and persistent login sessions.

How to Install the PWA

  1. Open Google Chrome or Microsoft Edge and navigate to your 3CX Web Client URL.
  2. Log in with your credentials (and 2FA code if enabled).
  3. Look for the install icon in the browser address bar — it appears as a small monitor with a down arrow, or a "+" icon.
  4. Click the install icon and confirm the installation. The 3CX PWA will be added to your dock (Mac) or taskbar (Windows) as a standalone app.
  5. Set Chrome or Edge to launch on startup in your system preferences — this ensures the PWA is running and can deliver call notifications even after a restart.

Benefits of the PWA

  • Desktop notifications — incoming calls trigger a system notification, just like a native app.
  • No repeated logins — the PWA keeps your session active between browser restarts.
  • Auto-updates — the PWA always runs the latest version of the 3CX web client without manual downloads.
  • Cross-platform — works identically on Mac, Windows, and Linux.

For desktop notifications to work, your browser must be running. Set Chrome or Edge to launch on startup and keep the PWA open. If you close the browser entirely, you will not receive incoming call alerts until it is reopened.

Need Help?

Email support@dvgvoip.com to open a ticket — we'll respond within one business day. You can also call (807) 700-7111 during business hours (Mon–Fri, 9 AM – 5 PM ET).

Secure Your Phone System Today

DVGVoIP configures 2FA, firewall rules, and encryption as part of every deployment — security is not an add-on.

Get Your Free Assessment →
Ask AI

Accessibility