Blog · Security
Turn on two-factor for Tally, mail, and panel logins
A shared password on WhatsApp is still the most common way cloud books get exposed. Two-factor (2FA) does not replace good passwords — it stops a leaked password from becoming a silent login at 2 AM.
Start where damage is largest
- Hosting / cloud panel and billing login
- Business email (Workspace, Titan, or your mail host)
- Remote desktop or gateway used for Tally on Cloud
Enable one surface at a time. Keep recovery codes printed in a sealed envelope with the owner — not in the same chat as the password.
Avoid locking the accounts desk
Pick an authenticator app on a phone the user actually carries. SMS-only 2FA is better than nothing, but SIM swaps happen. For shared owner accounts, prefer named logins so you can revoke one person without resetting everyone. When staff leave, combine 2FA cleanup with the same-day revoke steps in offboarding cloud access.
What “done” looks like
- Admin panel requires a second factor
- Mail admin and at least owner mailboxes use 2FA
- Remote access is not a single shared Windows password on a sticky note
Need help sequencing this on a managed stack? Contact KC Cloud or raise a support ticket.
KC