How do I sign in and secure my access?
You sign in with an email address and password, with a passkey and no password, or through the company account at Microsoft Entra. You secure the access with a second factor and the recovery codes that come with it. A forgotten password is reset with a one-time code sent to your address.
As at:September 2026
The three routes into an account
Which route is open is decided by the business. Open registration can be blocked, and then only people who have been invited can create an account.
How an account is created.
| Route | How it works | When it fits |
|---|---|---|
| Register yourself | Enter the email address, enter the confirmation code from the email, then set a name and password. | The first person in a business. They thereby become management. |
| Through an invitation | The link leads into registration with the assignment pre-filled. | Everyone else in a business. |
| Through the company account | Signing in through Microsoft Entra. Anyone without an account yet gets one on first sign-in. | Businesses that manage their accounts centrally anyway. |
Register yourself
- How it works
- Enter the email address, enter the confirmation code from the email, then set a name and password.
- When it fits
- The first person in a business. They thereby become management.
Through an invitation
- How it works
- The link leads into registration with the assignment pre-filled.
- When it fits
- Everyone else in a business.
Through the company account
- How it works
- Signing in through Microsoft Entra. Anyone without an account yet gets one on first sign-in.
- When it fits
- Businesses that manage their accounts centrally anyway.
If an address is already registered, no second account is created. Instead a notification email goes to that address.
Forgotten password
The reset runs in three separate steps. Setting the new password cannot be reached at all without the verified code.
The confirmation email at the end is part of the protection and not decoration: it reaches the account holder even where somebody else did the reset.
- Request the reset with your own address.
- Enter the one-time code from the email.
- Set the new password.
- Read the confirmation email. If it arrived unexpectedly, somebody else started the process.
- The one-time codes expire by themselves; they do not sit permanently in the database.
- The route requires a reachable mailbox. There is no reset via security questions, by phone or through support.
- If the mailbox is no longer reachable, management can set a new password in the personnel file.
Second factor and recovery codes
The second factor is a time-based one-time code. It is set up through a QR code in an authenticator app, the first code is verified, and after that it is active. Anyone can switch it off for their own account themselves.
Recovery codes come with every setup. Each is usable once and is intended for the case where the device with the authenticator app is gone. They can be regenerated, and the old ones then expire.
Without a password: passkeys
A passkey replaces the password with what the device already secures anyway: a fingerprint, face recognition or the device PIN. Registration and sign-in run on the WebAuthn standard.
The registered passkeys appear in an overview of their own and can be removed there individually. Several devices are possible.
Signing in to the app
The app can be signed in by QR code: the web interface generates a short-lived token, the app reads the code, and you are signed in without typing a password on the phone.
After that the app keeps its session through a refresh token that is managed on the server and invalidated on sign-out. Anyone belonging to several businesses picks one after signing in and switches later without signing in again.
The steps here describe a running system. Anyone who does not have one yet sets it up during the trial and keeps everything created along the way.
Changing the email address
The sign-in address is changed through a one-time code sent to the new address. The old address is informed, and the change can be undone from that message.
That is not convenience but protection against account takeover: anyone who gains access and swaps the address would otherwise be sole master of the account.
What the security section shows
Password changes, the second factor, passkeys and the account's security messages sit together in one place in the user settings.
The application also warns there when a password is used that appears in known data breaches. It urges a change; it does not lock the account.
Support access
Without action by the business nobody from support gets into the data. Management generates an access token with which support can look into the business for a limited time.
The access can be revoked at any time, by both sides: by the business and by support itself.
How the businesses are separated from one another
Every query is bound to the business. On top of that, dedicated guards check every identifier passed in against the acting business, and they fail closed: if even one of them does not belong, the operation aborts.
Those guards are needed because several references point to cross-business tables. A foreign identifier slipped in would be accepted by the database there; the check would not.
The separation is logical, not physical: all businesses sit in the same database, separated by columns and checks. The interface never sends an invalid identifier, so a breach is an attempt at manipulation and not an operating error.
Follow-up questions
- I can no longer access my email. How do I get into my account?
- Not through the reset: the one-time code goes to your mailbox, and there is no second route via security questions, phone or support. Management can set a new password for you in the personnel file, and that is the intended route.
- I have lost the phone with the authenticator app.
- That is what the recovery codes are for. Each is usable once. After that you set the second factor up again and generate new codes, and the old ones expire.
- Can we block open registration?
- Yes. Then only people who have received an invitation can create an account. The invitation link leads into registration with the assignment pre-filled.
- Can support simply look into our data?
- No. It takes an access token that management generates itself, and it is time-limited. Both sides can revoke it at any time, the business and support.
- Is our data in a database of its own?
- No, the separation is logical: all businesses sit in the same database and are separated by columns and checks. Every query is bound to the business, and dedicated guards additionally check every identifier passed in.
Describes the state of the application onSeptember 2026. What changes in the product is in the product updates.
Published by: AMNAU GmbH
Editorial responsibility: Ugur Aydogan, Product development.
Last reviewed: September 2026
Reading up is one thing. Setting it up yourself takes an afternoon.
MetronHR records working time at the terminal, in the app and in the browser, keeps holiday and overtime up to date and files the month ready to go. Try it free for 14 days.
No credit card, cancel at any time