Have a question about two-factor authentication (2FA)?
We’re introducing SMS based two-factor authentication (sometimes called 2FA) for areas of Rightmove Plus that contain personal data.
Two-factor authentication means that to gain access to Rightmove Plus you need both:
- something you know – your password
- something you have – your mobile phone
You’ve probably used a form of two-factor authentication before – to log in to your online bank accounts for example.
Protecting your leads, listings and your brand reputation
If a fraudster gets access to your Rightmove Plus account by taking control of your email inbox or tricking you into revealing your password with a phishing scam, they could steal your leads, upload fake listings in your brand name and potentially put your company at risk of having to report to the ICO.
We’re doing everything we can to prevent that from happening.
How it will work when you access areas of Rightmove Plus that contain personal data?
SMS two-factor authentication means that to gain access to Rightmove Plus you need both:
- something you know – your password
- something you have – your mobile phone
You’ve probably used a form of two-factor authentication before – to log in to your online bank accounts for example.
How it will work when you access areas of Rightmove Plus that contain personal data:
You: Enter your login details and password as usual and access one of:
- Lead Reports
- Opportunity Manager
- Viewings Manager
- User Management
- Add & Edit Properties
All other areas of Rightmove Plus will not require 2FA.
We: Send you a one-time passcode via text message to your mobile phone. The one-time passcode will be valid for 20 minutes.
You: Type in the one-time passcode and proceed as usual.
What areas of Rightmove Plus will require two-factor authentication?
- Lead Reports
- Opportunity Manager
- Viewings Manager (including Tenant Referencing)
- User Management
- Add & Edit Properties
Your branch might not have access to all of these reports or you might not have permission to see all of them.
Lead Reports and Add & Edit properties is currently restricted outside the normal working hours of an estate agent
Currently we restrict access to Lead Reports (available weekdays only) and Add & Edit property (available 7 days a week, but not overnight). Once the rollout of 2FA is complete we won’t have to limit access in Rightmove Plus. That way we’ll keep the fraudsters out of your account and give you access to all the information you need, when you need it.”
What areas of Rightmove Plus will NOT require two-factor authentication?
- Best Price Guide
- Market Share Reports
- Property Performance Reports
- Marketing Reports
I update my properties via my agency software (CRM) will I be affected by 2FA?
We do recommend that you speak to your agency software supplier about security options. If they have two-factor authentication available, we recommend that you enable it. We’ve spoken to agents who have experienced a fraudster accessing their agency software/CRM to upload fake properties and access their customer information. We also recommend you follow the same best practice that we recommend for Rightmove Plus with your agency software/CRM – for example, making sure your password is unique and not sharing logins with anyone else.
You will still need to verify your identity using 2FA in Rightmove Plus if you access any of the other reports that contain personal data in Rightmove Plus.
Will I have to use 2FA every time I login and access one of these reports?
- You’re using a browser (such as Chrome or Internet Explorer) or a device (such as a tablet, new PC or mobile) that you’ve not logged in with before.
- Your internet cookies have been deleted. We remember that you’ve logged on and verified using 2FA before by using “cookies” (small files saved on your browser). It may be that your computer is set to regularly clear cookies which will mean that you will have to go through this process again, each time the cookies are cleared.
OR
If your IT policy is set to clear cookies you may have to verify your identity more often. Ask your IT provider to help you change your settings if you don’t want to have to verify using 2FA each time or email us at 2FAHelp@rightmove.co.uk for help.
I’ve received an email about setting up 2FA but I wasn’t trying to set it up/haven’t logged in to Rightmove Plus – what’s going on?
When I click the button in the email to set up 2FA it opens in a different browser to the one I use – and now I get stuck in a loop trying to login and set up 2FA– what do I do?
When you click the button to confirm your email address, it will open Rightmove Plus in your default web browser (such as Microsoft Edge or Chrome). That means that you won’t be logged in to Rightmove Plus in that browser and you’ll have started the 2FA set up in another browser. To complete setting up 2FA and use your preferred browser you’ll need to reset your default browser.
Follow these steps to reset your default browser on a Windows machine:
- On your computer, click the Start menu.
- Click Settings (look for a cog symbol).
- Open “Apps” and go to “Default Apps”.
- At the bottom, under “Web Browser,” click your current browser.
- In the “Choose an app” window, click your preferred browser.
After resetting your default browser, you need to go back to the 2FA set up email and click the button again. This should take you through the 2FA set up process using your preferred browser.
One-time Passcodes
[expandsub1 title=”How long will the one-time passcode be valid?” rel=”submenu-highlander” tag=”h6″]The one-time passcode will be valid for 20 minutes. If you don’t manage to use the passcode in Rightmove Plus before the passcode expires, you’ll need to request a new passcode.
[/expandsub1]
[expandsub1 title=”I got a “this doesn’t look right” message when I typed in my passcode – what does that mean?” rel=”submenu-highlander” tag=”h6″]It may mean that either:
- The passcode has expired
- There was an error or typo when you put in the code
Try retyping the code and if that doesn’t work, request a new passcode.
[/expandsub1]
My passcode hasn’t come through – what do I do?
Using a mobile phone for 2FA
I need to update the mobile phone number I use for 2FA in Rightmove Plus/I lost my phone?
Let us know as soon as possible, in writing, by sending an email request to 2FAHelp@rightmove.co.uk. Please write the email from the inbox that your Rightmove Plus is associated with. We will carry out security checks to verify your identity.
Does it cost money/use up my data to receive the one-time passcode via SMS?
No. Receiving a text doesn’t cost money and it doesn’t use data allowance.
Do I need to be need to be on wifi/connected to the internet to receive my one-time passcode?
No. SMS does not require an internet connection. You do need to have mobile network connection to receive your one-time passcode.
I don’t have a company mobile so how do I set up 2FA?
If you have a personal mobile phone and your own Rightmove Plus account, you can use your own phone to receive your one-time passcodes. It doesn’t cost you anything and your phone number is not used for anything other than receiving your one-time passcodes for Rightmove Plus.
[expandsub1 title=”I don’t want to use my mobile – how do I use Rightmove Plus?” rel=”submenu3-highlander” tag=”h6″]If you don’t have a mobile phone you can still use Rightmove Plus, but you will be limited to using the parts of Rightmove Plus that don’t contain personal data such as the Best Price Guide.
If you need to access to areas of Rightmove Plus that contain personal data or might be used to upload fake listings and are unable to use a mobile phone to receive your SMS passcode, please let us know.
We can help if you have technical or practical challenges around you and your team adopting 2FA. We want to help you to take every step to reduce the very real threat to your business from fraudsters getting into your account. We’ve created a specialist team to help you 2FAHelp@rightmove.co.uk or phone us at 01908 712357.
Why have you chosen an SMS based type of two-factor authentication?
In November 2020, we surveyed agents who use Rightmove Plus to find out which method of two-factor authentication they would prefer. Options included SMS based 2FA or an authenticator app. 2/3 of the agents who responded said they preferred that we use SMS to send a passcode to their mobile phone. We’ve listened to that feedback and developed two-factor authentication using the method that the majority of agents told us was their preference.
Shared Logins
Why is having separate logins so important?
If your staff log into your Rightmove Plus account using a Gmail/Hotmail/Yahoo account or you share one login across your entire team, imagine what would happen if they were to leave your estate agency for a competitor? Unless you contact us and ask for the email address to be removed or update the password for everyone who is sharing the account, they will still be able to access your properties and see new listings making it easier for them to target your new instructions. What’s more they can see potential leads (which contain applicants’ personal data) and your confidential market share reports. Keep your accounts secure by having individual email addresses under your own domain.
Not only that, but shared logins will make two-factor authentication tougher. Many people may use quite simple passwords when they share logins, so that makes your account that much easier for a fraudster to compromise.
Benefits of having your own domain email address
- Keep your data secure and away from competitors when branch staff leave
- If a data breach were to occur, as a joint data controller, you are responsible for the security and protection of personal data and you may be required to provide the ICO with evidence of: an audit trail of exactly who in your branch accessed your Rightmove Plus account and when, confirm what security steps you had in place to prevent the sharing of logins and passwords and provide evidence of accountability and responsibility for each of your branch staff
- Provides greater protection to avoid unauthorised accessed to your Rightmove Plus account
- Instils trust and reassurance with vendors, landlords, buyers and tenants
- Makes two-factor authentication easier
How do I create my own domain email addresses?
Step 1 – Check that you have a domain name
If you have already have a website, then you already have a domain name.
If you do not have a website, then we would strongly recommend you set one up as many vendors and landlords will check out the agent’s own websites when selecting an agent to instruct.
Although we are unable to recommend a website designer or IT firm, a Google Search should give you a few options. We suggest you look at reviews of potential suppliers and check out their work on other companies’ websites.
Step 2 – Contact your domain provider
Speak to your website hosting provider, they will be able to set you up with a domain email address. Many offer this free as part of their website package, however some may charge a small fee. You can often log into your own account and it will give you an option to add an email address.
I need to update the mobile phone number I use for 2FA in Rightmove Plus/I lost my phone?
Let us know as soon as possible, in writing, by sending an email request to 2FAHelp@rightmove.co.uk. Please write the email from the inbox that your Rightmove Plus is associated with. We will carry out security checks to verify your identity.
Does it cost money/use up my data to receive the one-time passcode via SMS?
Do I need to be need to be on wifi/connected to the internet to receive my one-time passcode?
No. SMS does not require an internet connection. You do need to have mobile network connection to receive your one-time passcode.
I don’t have a company mobile so how do I set up 2FA?
If you have a personal mobile phone and your own Rightmove Plus account, you can use your own phone to receive your one-time passcodes. It doesn’t cost you anything and your phone number is not used for anything other than receiving your one-time passcodes for Rightmove Plus.
[expandsub1 title=”I don’t want to use my mobile – how do I use Rightmove Plus?” rel=”submenu3-highlander” tag=”h6″]If you don’t have a mobile phone you can still use Rightmove Plus, but you will be limited to using the parts of Rightmove Plus that don’t contain personal data such as the Best Price Guide.
If you need to access to areas of Rightmove Plus that contain personal data or might be used to upload fake listings and are unable to use a mobile phone to receive your SMS passcode, please let us know.
We can help if you have technical or practical challenges around you and your team adopting 2FA. We want to help you to take every step to reduce the very real threat to your business from fraudsters getting into your account. We’ve created a specialist team to help you 2FAHelp@rightmove.co.uk or phone us at 01908 712357.
Why have you chosen an SMS based type of two-factor authentication?
Why is having separate logins so important?
If your staff log into your Rightmove Plus account using a Gmail/Hotmail/Yahoo account or you share one login across your entire team, imagine what would happen if they were to leave your estate agency for a competitor? Unless you contact us and ask for the email address to be removed or update the password for everyone who is sharing the account, they will still be able to access your properties and see new listings making it easier for them to target your new instructions. What’s more they can see potential leads (which contain applicants’ personal data) and your confidential market share reports. Keep your accounts secure by having individual email addresses under your own domain.
Not only that, but shared logins will make two-factor authentication tougher. Many people may use quite simple passwords when they share logins, so that makes your account that much easier for a fraudster to compromise.
Benefits of having your own domain email address
- Keep your data secure and away from competitors when branch staff leave
- If a data breach were to occur, as a joint data controller, you are responsible for the security and protection of personal data and you may be required to provide the ICO with evidence of: an audit trail of exactly who in your branch accessed your Rightmove Plus account and when, confirm what security steps you had in place to prevent the sharing of logins and passwords and provide evidence of accountability and responsibility for each of your branch staff
- Provides greater protection to avoid unauthorised accessed to your Rightmove Plus account
- Instils trust and reassurance with vendors, landlords, buyers and tenants
- Makes two-factor authentication easier
How do I create my own domain email addresses?
Step 1 – Check that you have a domain name
If you have already have a website, then you already have a domain name.
If you do not have a website, then we would strongly recommend you set one up as many vendors and landlords will check out the agent’s own websites when selecting an agent to instruct.
Although we are unable to recommend a website designer or IT firm, a Google Search should give you a few options. We suggest you look at reviews of potential suppliers and check out their work on other companies’ websites.
Step 2 – Contact your domain provider
Speak to your website hosting provider, they will be able to set you up with a domain email address. Many offer this free as part of their website package, however some may charge a small fee. You can often log into your own account and it will give you an option to add an email address.
If you share logins, we can help you set up separate accounts for everyone in your team.
Here’s how…
Set up separate accounts for everyone in your team >
How can we help?
We can help if you have technical or practical challenges around you and your team adopting 2FA. We want to help you to take every step to reduce the very real threat to your business from fraudsters getting into your account. We’ve created a specialist team to help you 2FAHelp@rightmove.co.uk or phone us at 01908 712357.