Scenario 1: User has not added their SAP Concur account on an authenticator app or browser extension and is entering the manual key in the Authentication Code field.
The
Authentication Code field is where you should enter the six-digit code generated by the Authenticator app AFTER you have added the account in the authenticator app using the key provided by SAP Concur.
To set up 2FA, you should download an authenticator app (if you don't have one already) and add an account within the authenticator app, using either the QR code or the manual key. After the account is added, the authenticator app will display a six-digit code that you should copy and enter in the
Authentication Code field in the SAP Concur Sign In page. For resources on setting up 2FA, please read:
How Do I Set Up Two-Factor Authentication (2FA)?
Scenario 2: The code you are trying to enter has already expired.
The authentication code is time-based and expires every 30 seconds. Please make sure that the authentication code entered is still active in the Authenticator app.
Scenario 3: The time on the user's mobile device is not synchronized.
Please follow the steps below to fix this issue:
iOS devices:
- On your iPhone, go to Settings
- Scroll down, then select General
- Scroll down, then select Date & Time
- Select Set Automatically to true
- Close and reopen the Authenticator app
- Enter the authentication code shown on the app
Android devices:
- Go to the main menu of the Authenticator app
- Select the three dots in the top right corner
- Select Settings
- Select Time correction for codes
- Press Sync now
- The message displayed will confirm if the time has been synchronized or if it was already correct
- Close and reopen the Authenticator App
- Enter the authentication code shown on the app
If you are using an Android device and the Google Authenticator app, please follow these steps:
- Go to the main menu of the Google Authenticator app
- Click the three dots in the upper right corner
- Select Settings
- Select Time correction for codes
- Select Sync now
- The message displayed will confirm if the time has been synchronized or it it was already correct
- Close and reopen the authenticator app
- Enter enter the authentication code in to SAP Concur again
Scenario 4: The time on the user's laptop or computer is not synchronized.
When using the Google Authenticator extension for Google Chrome, first be sure you have pinned the Authenticator app so it is more easily accessible. Once pinned, follow these steps:
- Click the Authenticator icon to open the extension
- When the Authenticator opens, click the cog wheel icon in the upper-left corner to open settings
- Click Sync Clock with Google
- Click Allow to give permission to "Read and change your data on www.google.com on the pop-up if shown (Optional)
- The message displayed will confirm if the time has been synchronized
Scenario 5: The user has simultaneously opened the 2FA enrollment page in more than one browser window and added the account using the QR code or secret key from the first window that was opened.
Every time you open the Enroll in 2FA page, we initialize the 2FA secret on the database and a unique QR code and secret key are displayed. However, we only honor the latest initialized secret. Therefore, if you opened the Enroll in 2FA page in two different browsers or in a browser and in the mobile app, the only QR code and manual key that will work will be the ones from the page that was opened last. If that is the case, you should delete the account you had created in the authenticator app or extension, and add a new account using the latest generated QR code or manual key.
Scenario 6: User is entering a space between the first three and last three digits of the six-digit code.