Why account security matters
Your Frontu account holds customer details, work orders, prices and your team's data. Most security incidents start with one account that has too much access or a weak login.
The steps below use features already in Frontu. Following them lowers the risk a lot.
1. Turn on two-factor authentication (2FA)
With 2FA, logging in takes the password and a 4-digit code sent to the user's email. A stolen password alone isn't enough to get in. 2FA works on the web and in the Frontu mobile app.
For the whole account (recommended): Go to Settings. Turn on Enforce two-factor authentication. From the next login, 2FA is switched on automatically for every office user and app user. Customer portal users aren't affected.
For individual users: An Administrator can tick 2-Factor Authentication when creating or editing a user. Each user can also turn it on in their own Profile.
Tip: make sure every user's email address is correct and belongs to them only. That's where the codes are sent.
More details: Two-factor authentication (2FA)
2. Sign in with Google or Microsoft with single sign-on (SSO)
Users log in to Frontu with their company Google or Microsoft account instead of a separate Frontu password. It works on the web and in the Frontu mobile app.
Why it helps:
Your company's own login rules also apply to Frontu. That includes password rules and multi-factor authentication in Google or Microsoft.
Fewer passwords for people to remember, reuse or write down.
If you block someone's company account, they can no longer log in to Frontu with SSO.
How to get it:
Contact Frontu support and ask for SSO to be switched on for your account.
Make sure each user's email in Frontu is exactly the same as their Google or Microsoft work email. SSO matches users by email and doesn't create new users.
Users then click Sign in with Google or Sign in with Microsoft on the login page.
Note: logging in with a Frontu password still works alongside SSO.
More details: Single sign-on (SSO)
3. Keep the number of Administrators small
An Administrator can do everything in the account. That includes managing users, permission groups, settings and API access. Only an Administrator can make someone else an Administrator.
Our recommendations: Give the Administrator role to as few people as possible. Two is a good number: one main person and one backup. Frontu doesn't let you archive the last Administrator, so you can't lock yourself out. A second Administrator means you still have access if one person is away or leaves.
Everyone else, such as dispatchers, office staff and managers, should have the User role with a suitable permission group.
4. Use permission groups to give "just enough" access
A permission group decides which menu items a user sees and what they can do in each one:
Forbid: the user can't see the item.
View: the user can look at records but can't change them.
Create: the user can add new records.
Modify only: the user can edit existing records but can't add new ones.
Modify: the user can add and edit records.
Archive: the user can archive records.
Recommended setup: Create a separate group for each job role, for example "Dispatcher", "Office" and "Viewer / Management". Set sensitive areas to Forbid unless the role really needs them
More details : Permission groups
5. Watch for "New login" emails
When an office user logs in from a device or browser Frontu doesn't recognise, they get an email called "New login to your Frontu account". It shows the time, IP address and browser.
If it was them, they click This was me.
If not, they click This wasn't me and change their password right away. They should also tell your Administrator.
More details: Stay in Control of Every Login: New Device Security
6. Protect your integrations (API tokens)
If you connect Frontu to other systems, such as an ERP or automation tools, those connections use API tokens.
Only Administrators or users you trust should have access to API settings.
Use a separate token for each integration, so you can switch one off without breaking the others.
Revoke tokens that are no longer used, and any token you think may have leaked.
Never share tokens by email or chat.
7. Built-in protection you get automatically
Lockout after failed logins: after repeated wrong passwords, web login is blocked for 15 minutes. This stops password-guessing attacks.
One device per technician: a technician logged in on one phone can't silently log in on another.
Securely stored passwords: passwords are stored with one-way hashing and are never kept in readable form.
8. Good everyday habits
Archive users as soon as they leave your company even if you use SSO.
Don't share logins. Give each person their own user, so permissions and history stay accurate.
Use strong, unique passwords, and don't reuse passwords from other services.
Log out on shared computers.
Quick checklist:
Enforce two-factor authentication turned on
SSO with Google or Microsoft switched on (ask Frontu support)
Only 2 or a few Administrators
A permission group per role, with Users, Settings and API settings forbidden for most
New login device notifications on;
Unused API tokens revoked
Former employees archived
User and permission review every few months