Action required: MFA becomes mandatory on 15 October

From Thursday, 15 October 2026, Multi-Factor Authentication (MFA) will be required for all Tall Bob users. If you have not set it up by then, you will be prompted to do so before you can continue using your account. Setting it up now takes about a minute; follow the steps below.

Multi-Factor Authentication (MFA) adds a second layer of security to your Tall Bob account. Instead of relying on your password alone, you also enter a short, single-use code generated by an authenticator app on your phone or desktop.

TABLE OF CONTENTS


Why we use MFA

Your Tall Bob account can send messages to your customers on your brand's behalf, and it holds your contact data, sender addresses, API credentials, and billing settings. If someone else gets into it, the damage is immediate and public.

Passwords alone are no longer enough to protect that:

  • Passwords leak. Credentials exposed in unrelated data breaches are collected and replayed against other services. If a password has ever been reused anywhere else, it should be treated as already known.
  • Phishing is convincing. A well-built fake login page will capture a password in seconds, often from someone who is busy and moving fast.
  • The blast radius is large. An attacker in a messaging account can send fraudulent SMS to your customer base, damage sender reputation, burn through account credit, or quietly issue API credentials to keep access later.
  • Reputation is hard to rebuild. A scam message that appears to come from your business erodes customer trust far more than the cost of the messages sent.

MFA closes this gap. Even if your password is stolen, an attacker cannot log in without the time-based code on your device. It is one of the single most effective controls available, and it takes about a minute to set up. It also supports the security expectations many of our customers hold themselves to: access control, individual accountability, and an audit trail of who did what.


Choosing an authenticator app

Tall Bob uses standard time-based one-time passwords (TOTP), so any standards-compliant authenticator app will work. You only need one.

If your business is not already using an authenticator app, below are some examples that are compatible with Tall Bob:

AppBest forNotes
Google AuthenticatorSimplest option for most peopleFree, iOS and Android. Supports cloud backup to your Google account so codes survive a lost or replaced phone.
Microsoft AuthenticatorBusinesses already on Microsoft 365Free, iOS and Android. Handles your Microsoft sign-ins and third-party TOTP codes in one app.
1PasswordTeams who want passwords and codes managed togetherPaid. Stores the password and the MFA code for the same login, syncs across phone and desktop, and works well where access must be handed over cleanly between staff.
BitwardenA lower-cost password manager optionFree and paid tiers. Same combined password plus code approach as 1Password, available on mobile and desktop.
AuthyPeople who want a dedicated app with multi-device syncFree, mobile-only; the desktop apps were retired, so plan for a phone-based setup.

Also fine to use: Apple Passwords / iCloud Keychain (built into iPhone, iPad and Mac) if you are entirely in the Apple ecosystem.

A note on password managers: storing your MFA code in the same app as your password is more convenient and much better than not using MFA at all. It does mean one app protects both factors, so if you take that route, make sure that app is secured with a strong master password and its own MFA.

Practical tips before you start

  • Install and sign in to your chosen app before you begin the setup steps below.
  • If the app offers backup or sync, turn it on. This is what saves you if you lose your phone.
  • Do not screenshot the QR code and send it to anyone. It is the equivalent of sharing a key.


How to set up MFA

Setup takes about 30 seconds. Once saved, MFA is active on your account immediately.


How MFA works day to day

At login

  1. Enter your username and password at app.tallbob.com as usual.
  2. You will then be prompted for your MFA code unless you are on a device you have previously chosen to trust (see Trusted devices below).
  3. Open your authenticator app, find the Tall Bob entry, and enter the 6-digit code.

Codes refresh roughly every 30 seconds. If a code expires while you are typing, just wait for the next one; there is no need to start the login again. Your authenticator app generates these codes on the device itself, so it does not need mobile reception or internet access to work.


Trusted devices

When you are challenged for an MFA code at login, you can choose to trust that device. On a trusted device, you will not be asked for a code every time you sign in, which keeps day-to-day logins quick on your own computer or phone.

Two things are worth understanding about this:

  • Only trust devices that are genuinely yours. Never trust a shared, public, or borrowed computer. Trusting a device reduces how often your second factor is checked on it, so it should only ever be a machine you personally control.
  • Risky actions are still challenged. Trusting a device does not exempt you from step-up challenges. Even on a trusted device, you will still be asked for a current MFA code before any of the sensitive actions listed below.

That combination is deliberate. Routine logins stay convenient, while the actions that could actually cause damage are verified every time, on every device.


How long a device stays trusted

By default, a device stays trusted for 14 days. After that, you will be asked for an MFA code at your next login, and you can choose to trust the device again from there. Some accounts have a shorter trust period, for example, where a contractual or internal security requirement calls for it. If your account is set to a shorter window, you will simply be asked for a code more often. If you are not sure what applies to your account, ask your account owner or contact support@tallbob.com.


Revoking a trusted device

If a trusted device is lost or stolen, or belonged to someone who has left the business, revoke its trusted status so that a fresh MFA code is required the next time it is used. Do not wait for the 14 days to lapse. Any user with Manage User Permissions can do this:

  1. Go to User Access Management (app.tallbob.com/users/accessrights).
  2. Click the dot menu to the right of the affected user.
  3. Choose the option to revoke that user's trusted devices.

This clears trust for all of that user's devices, so they will be asked for an MFA code the next time they log in anywhere. Revoking trusted devices is itself a risky action, so you will be asked for your own MFA code to confirm it.

Worth noting when you assign privileges: Manage User Permissions is a powerful permission. It allows someone to reset another user's MFA and revoke their trusted devices, which are exactly the controls protecting the account. Grant it only to people who genuinely need to administer users.


Step-up challenges for risky actions

MFA is not only checked at login. Tall Bob will also ask you to re-enter a current MFA code when you perform a sensitive or high-impact action, even though you are already signed in. This applies even on a trusted device. This is often called a “step-up” challenge.

Actions that may trigger a fresh MFA challenge:

  • Changing your password
  • Updating your MFA settings
  • Viewing or updating API Credentials
  • Managing user permissions, editing or adding new users
  • Managing your billing details
  • Adding new Sender Addresses to your account
  • Configuring webhooks and integrations

This is deliberate, and it is a good thing. If someone does manage to hijack an active session, the step-up challenge stops them at the point where they would try to make their access permanent, such as adding a user they control, issuing themselves API keys, redirecting your data to their own webhook, or adding a sender address to impersonate your brand.

What to do when challenged: simply open your authenticator app and enter the current code, the same way you do at login. Keep your authenticator app within reach when you are doing account administration or setting up an integration.


Shared logins: please move away from them

If several people in your team currently sign in with the same Tall Bob username and password, we strongly recommend moving to one login per person. Shared accounts and MFA do not work well together, and the problems are practical rather than theoretical:

  • MFA gets tied to one person's device. Whoever scanned the QR code becomes a bottleneck; everyone else has to ask them for a code to log in or to clear a risky-action challenge.
  • You lose the audit trail. When something needs to be traced, “the shared account did it” is not an answer. Individual logins tell you who sent what and who changed which setting.
  • Offboarding becomes a scramble. When a staff member leaves, a shared password has to be changed and MFA re-enrolled for everyone. With individual users, you simply remove that one user.
  • Permissions cannot be scoped. Everyone sharing a login has identical access, so people end up with more than their role requires.
  • Credentials spread. Shared passwords get passed around in chat messages, emails, and spreadsheets, and they tend to stay there.
  • Lockouts hit everyone at once. If the person holding the shared MFA loses their phone, the token has to be reset for the whole account, and every user is disrupted. With individual logins, your account owner or anyone with Manage User Permissions can reset just that one person's MFA and no one else is affected.


What to do instead

  1. Create a separate user for each person who needs access. Check out the User Access Management article, which includes an Adding a New User walkthrough.
  2. Have each person set up MFA on their own device using the steps above.
  3. Give each user only the access their role requires.
  4. Retire the shared login, or change its password and restrict it once everyone has moved across.


Good practice and troubleshooting

Keep access to your own account

  • Turn on backup or sync in your authenticator app, or enrol a second device, so a lost phone does not lock you out.
  • If you are replacing your phone, migrate or re-enrol your authenticator before wiping the old device.

If your code is rejected

  • Wait for the next code and try again; the one you used may have expired mid-entry.
  • Check that the date and time on your device are set to update automatically. TOTP codes depend on an accurate clock, and a device running a few minutes out is the most common cause of valid-looking codes being refused.
  • Make sure you are reading the Tall Bob entry in your app, not a similarly named one.

If you lose your device or cannot access your codes

If you get a new phone, wipe a device before migrating, or delete the authenticator entry by mistake, your MFA token needs to be reset before you can log in again. There are two ways to do this.

Option 1: Ask a colleague who can administer users (usually fastest)

Your account owner, or any colleague with Manage User Permissions, can reset your MFA without waiting for support:

  1. Go to User Access Management (app.tallbob.com/users/accessrights).
  2. Click the dot menu to the right of the affected user.
  3. Choose the option to reset that user's MFA.

The user can then log in and set up MFA again from scratch, following the setup steps above.

Because resetting someone's MFA is itself a risky action, the person doing the reset will be asked for their own MFA code to complete it, so have your authenticator app to hand before you start.

If you hold this privilege, it is worth knowing you have this ability: a locked-out colleague can be back up and running in a minute rather than waiting on a ticket.

Option 2: Contact Tall Bob support

If no one with that access is available or if everyone who has it is locked out, email support@tallbob.com and we will reset your MFA after identity checks.

Stay alert to phishing

  • Tall Bob support will never ask you for your MFA code, and neither will anyone else legitimately. Treat any such request, by phone, email or message, as an attack.
  • Never approve a challenge or read out a code that you did not personally trigger. If a prompt appears unexpectedly, someone may have your password; change it and contact us.
  • Check that you are on app.tallbob.com before entering credentials.


Need a hand?

If you get stuck at any point, email us at support@tallbob.com or submit a ticket, and we will help you get set up.