MiroxMirox
  • Platform

    • Philosophy
    • Platform Overview
    • Platform Resources
  • Mirox-Cloud

    • Cloud Overview
    • Connected Microservices
  • Mirox-Agent

    • Agent Overview
    • Deployment Options
    • Data Scraper
    • Digital Twin
  • Technical Details

    • Metric Collection
  • Information

    • Supported Plants
  • Plant Types

    • Solar Plants
    • Wind Plants
    • Battery Storage
    • Alarm System
  • Monitoring & Visualization

    • Real-time Monitoring
    • Digital Twin
    • Component States
    • Inverter Status Codes
    • Inverter Events
    • Loss Detection
    • Power Limits & Curtailment
    • Efficiency Detection
    • KPI Dashboard
  • Data Management

    • Events
    • Alarm Levels
    • Tickets
    • Forecasts
    • Reports
    • Metrics
  • Alert Manager

    • Overview
    • Alert Rules
    • Alerts & Notifications
    • Examples
  • Integration & Sharing

    • Cooperations
    • API Tokens
    • VPN
    • VPN Address Conflicts
    • Proxy
  • AI

    • AI Assistant & Wizards
    • Agentic Access (MCP)
  • Billing

    • Market & Tariffs
    • How Revenue Is Calculated
    • Accounting & Billing
  • Collaboration

    • Invitations
  • Security

    • Authentication
    • Account Lockout
    • Organization Security Policy
    • Permission System
    • Network Segmentation
    • Cooperation Restrictions
    • Access Audit Logging
    • Activity & Audit Trail
  • Nodes

    • mrxnode
  • Application

    • Door Control
    • Generic Relay
  • Edge Cluster

    • Orchestration
  • Getting Started

    • Onboarding
    • Setup
  • Personal

    • Using the VPN
    • Using the Proxy
    • Two-Factor Authentication
    • Sessions
    • API Tokens
    • Notifications
    • Connect Microsoft Teams
  • Per Park

    • Contacts
    • Network Devices
    • Data Loggers
    • Generic Modbus Reader
    • Components
    • Direct VPN (per Agent)
    • Data Volume
    • History Import
  • Organization

    • Member Permissions
    • Security Policy
    • Cooperations
    • File Storage
    • VPN Services
    • Working with Reports
  • Data Export

    • Metric Export
    • Metric Export API
    • Migrating to the Metric Export
    • Legacy Export API
    • External Report Generation
    • Grafana
    • Grafana Dashboards
    • API Overview
    • MiroxQL Formulas (API)
  • Support

    • Request an Integration
  • mrxnode

    • Overview
    • How-To Guide
    • Container Deployment
    • Command Cheatsheet
    • Troubleshooting
  • Reporting

    • External Report Generator
    • Metric Export for Excel
  • Remote Access
  • Account Security
  • AI in Mirox
  • History Import
  • Reports
  • Data Export
  • English
  • Deutsch
  • Español
  • Français
  • Português
  • Italiano
  • English
  • Platform

    • Philosophy
    • Platform Overview
    • Platform Resources
  • Mirox-Cloud

    • Cloud Overview
    • Connected Microservices
  • Mirox-Agent

    • Agent Overview
    • Deployment Options
    • Data Scraper
    • Digital Twin
  • Technical Details

    • Metric Collection
  • Information

    • Supported Plants
  • Plant Types

    • Solar Plants
    • Wind Plants
    • Battery Storage
    • Alarm System
  • Monitoring & Visualization

    • Real-time Monitoring
    • Digital Twin
    • Component States
    • Inverter Status Codes
    • Inverter Events
    • Loss Detection
    • Power Limits & Curtailment
    • Efficiency Detection
    • KPI Dashboard
  • Data Management

    • Events
    • Alarm Levels
    • Tickets
    • Forecasts
    • Reports
    • Metrics
  • Alert Manager

    • Overview
    • Alert Rules
    • Alerts & Notifications
    • Examples
  • Integration & Sharing

    • Cooperations
    • API Tokens
    • VPN
    • VPN Address Conflicts
    • Proxy
  • AI

    • AI Assistant & Wizards
    • Agentic Access (MCP)
  • Billing

    • Market & Tariffs
    • How Revenue Is Calculated
    • Accounting & Billing
  • Collaboration

    • Invitations
  • Security

    • Authentication
    • Account Lockout
    • Organization Security Policy
    • Permission System
    • Network Segmentation
    • Cooperation Restrictions
    • Access Audit Logging
    • Activity & Audit Trail
  • Nodes

    • mrxnode
  • Application

    • Door Control
    • Generic Relay
  • Edge Cluster

    • Orchestration
  • Getting Started

    • Onboarding
    • Setup
  • Personal

    • Using the VPN
    • Using the Proxy
    • Two-Factor Authentication
    • Sessions
    • API Tokens
    • Notifications
    • Connect Microsoft Teams
  • Per Park

    • Contacts
    • Network Devices
    • Data Loggers
    • Generic Modbus Reader
    • Components
    • Direct VPN (per Agent)
    • Data Volume
    • History Import
  • Organization

    • Member Permissions
    • Security Policy
    • Cooperations
    • File Storage
    • VPN Services
    • Working with Reports
  • Data Export

    • Metric Export
    • Metric Export API
    • Migrating to the Metric Export
    • Legacy Export API
    • External Report Generation
    • Grafana
    • Grafana Dashboards
    • API Overview
    • MiroxQL Formulas (API)
  • Support

    • Request an Integration
  • mrxnode

    • Overview
    • How-To Guide
    • Container Deployment
    • Command Cheatsheet
    • Troubleshooting
  • Reporting

    • External Report Generator
    • Metric Export for Excel
  • Remote Access
  • Account Security
  • AI in Mirox
  • History Import
  • Reports
  • Data Export
  • English
  • Deutsch
  • Español
  • Français
  • Português
  • Italiano
  • English
  • FAQ

    • Remote Access — Frequently Asked Questions
    • Account Security — Frequently Asked Questions
    • AI in Mirox — Frequently Asked Questions
    • History Import — Frequently Asked Questions
    • Reports — Frequently Asked Questions
    • Data Export — Frequently Asked Questions

Account Security — Frequently Asked Questions

The questions people ask about signing in, being signed out and two-factor authentication (2FA). For how sign-in works, see Authentication; for the rules an organization can set, see Organization Security Policy.

Signing In and Being Signed Out

1. Why was I signed out?

A sign-in does not last forever. When its time is up, you are signed out and sign in again: with your password, plus your 6-digit code or your passkey if your account has two-factor authentication (2FA). The sign-in page says why you were signed out, and after signing in you return to the page you were on.

How long a sign-in lasts is set by your organization. Without a rule of its own, the Mirox defaults apply: 1 year in the web app and 1 year in the mobile app. If your organization has set a 2FA re-check interval, accounts with 2FA sign in again more often, see question 3.

Other reasons for a sign-out:

  • Your organization changed its rules (question 4), or you joined an organization with stricter rules.
  • The session was signed out from the sessions list in your profile.
  • Your password was reset. A password reset signs you out everywhere, including the mobile app.
  • Mirox support reset your second factor (question 7).

See How Long a Sign-In Lasts.

2. What is the countdown in the header?

It shows how long your sign-in in this browser still lasts. The countdown appears during the last 24 hours. Shortly before the end Mirox warns you again. Then the sign-in page appears with a sentence that says why.

There is no half-open state: you are either signed in or you sign in again. Text you typed into a form and did not save is lost when the sign-in ends, so save before the countdown runs out. See The Countdown in the Header.

3. Why do I sign in more often now that I have 2FA?

Only if your organization has set a 2FA re-check interval. By default there is none. With an interval, an account with 2FA (authenticator app or passkey) is signed out a set time after it last proved its second factor on that sign-in, for example every 7 days in the web app. Your organization sets the interval separately for the web app and the mobile app. You are never asked for a code in the middle of your work. You are signed out, and you sign in again with password and code or passkey.

The reason: a second factor only protects your account if it is presented regularly. Without this, a browser left signed in could be used for weeks without the code. Accounts without 2FA only follow the sign-in duration. See 2FA Re-Check.

4. Why did everyone get signed out after a rule change?

Because running sign-ins follow the new rules. An organization can change its rules at any time:

  • If the rules get stricter, sign-ins that are now too old end a short time after the change, between about 10 and 70 minutes. Open browser tabs show a warning first.
  • If the rules get looser, sign-ins simply last longer. Nobody has to sign in again.

The change is recorded in the organization's activity log, with who made it. See When You Change the Rules.

5. Who decides these rules, and where do I see when my sign-in ends?

The Admins and Moderators of your organization set the rules on the organization's Security tab. Each value can be left on Platform default; then the Mirox defaults apply. If you belong to no organization, the Mirox defaults apply as well.

Your own sign-ins are listed on the Security tab of your profile: each browser or app, when it was last active and when it ends. You can sign out other sessions there. See Managing Your Sessions and, for Admins and Moderators, Setting Your Organization's Security Policy.

6. Does the mobile app sign me out too?

Yes, when its time is up. By default a sign-in in the mobile app lasts 1 year, which is the longest possible, and accounts with 2FA are not asked again before that. Your organization can set shorter values and a 2FA re-check interval for the app. When the time is up, the app shows the sign-in screen and you sign in again. See Mobile App.

Two-Factor Authentication

7. I lost my authenticator. What now?

If you still have your backup code: enter it on the code screen when you sign in. This signs you in and switches the authenticator app off for your account (question 8); a passkey stays. Set 2FA up again right away on the Security tab of your profile.

If you lost the backup code as well and have no passkey: contact Mirox support. Support can reset your second factor. This signs you out everywhere. Afterwards you sign in with your password and set 2FA up again.

See If You Lose Your Authenticator App.

8. What does the backup code really do?

The backup code is your emergency key for the day you cannot use your authenticator app. It is shown once, when you set 2FA up.

  • You can use it in one place only: on the code screen when you sign in.
  • Using it signs you in and switches the authenticator app off for your account; a passkey stays.
  • No new backup code is issued automatically. You get a new one when you set 2FA up again.

While your account has no second factor, the device proxy is closed for you, and plants of organizations that require 2FA are hidden (question 10). So set 2FA up again as soon as you are signed in. See Save Your Backup Code.

9. I typed the wrong code several times. Am I locked out?

Possibly, for a short time. A wrong code at sign-in counts like a wrong password. After 5 wrong attempts within an hour the account is locked for 15 minutes; further failures lock it for longer. Sign-in can also be paused for a whole network address after 10 failed attempts from it. Wait for the time shown, then try again with a fresh code. See Account Temporarily Locked.

Plants Hidden by a 2FA Requirement

10. Why are some plants missing?

Most likely the organization that owns these plants requires 2FA for plant access, and your account has no second factor. From the start date that organization set, you no longer see its plants: not in lists and dashboards, not on the plant pages, not through the device proxy, not in exports and not in Grafana. Grafana follows within about an hour, both when the rule starts and after you enable 2FA.

You stay signed in. Your profile, your settings and the organization pages keep working, and a hint in the header tells you to enable 2FA. As soon as you enable 2FA, the plants are back. Plants of other organizations are not affected.

The same happens after you signed in with your backup code, because that switches the authenticator app off, unless you also have a passkey (question 8). To enable 2FA, see Setting Up Two-Factor Authentication.

11. Does a partner organization's rule apply to me?

The 2FA requirement does. It belongs to the organization that owns the plant, so it also applies to you on the plants a cooperation partner shares with your organization. The cooperation list shows whether a partner requires 2FA.

The rules about sign-in duration do not. How long you stay signed in, and how often you sign in again with 2FA, always follows the organization you belong to. See Whose Rule Applies to Whom.

12. Do alarms still arrive?

Yes. Alarm notifications are always delivered on the channels you set up: email, push, Telegram and webhook. This also holds for plants that are hidden from you by a 2FA requirement, and it does not depend on how long your sign-in lasts. See Alarms and your sign-in.

13. Does our 2FA requirement apply to Mirox support?

No. Mirox platform administrators (Mirox support) are not subject to an organization's 2FA requirement. How support access works is described under Administrative Access.

What Is Not Affected

14. Do API tokens need 2FA?

No. API tokens are made for automation. A token is never asked for a second factor, and it is not ended by the rules for sign-in duration. It keeps working until it expires or you revoke it.

One rule applies: while your own organization requires 2FA and your account has no second factor, you cannot create a new token. Your existing tokens keep working. See Tokens and Two-Factor Authentication.

15. Does the VPN depend on 2FA?

No. The VPN is certificate-based. It depends neither on your sign-in to the web app or the mobile app nor on 2FA: being signed out does not disconnect it, and a 2FA requirement does not change your routes. Because the certificate is the key, keep it safe and revoke it at once if a device is lost. See VPN.

16. Why can I not open a device through the proxy?

The device proxy has two conditions of its own, whatever your organization's rules say:

  • A second factor on your account, an authenticator app or a passkey. Without it the proxy opens no device.
  • A live sign-in that completed the second-factor step (code or passkey). When you sign out, or the session ends or is signed out somewhere else, the next request to the device is refused. A live stream that is already open is closed within about a minute.

A proxy link shared by a colleague works the same way: you need your own sign-in with 2FA, and the permission on the plant. See Proxy.

17. Do the AI assistant and Grafana follow my sign-in?

Yes, both do.

  • The AI assistant in the app acts for you while you are signed in. It sees what you may see, so not the plants hidden by a 2FA requirement, and it stops when your sign-in ends. External AI tools that connect with an API token follow the token rule instead (question 14).
  • Grafana follows your Mirox sign-in. When the sign-in ends, an open dashboard stops loading data until you sign in again. A wall display that runs under a personal account is therefore signed out when that account's sign-in ends. See Grafana Follows Your Mirox Sign-In.

Passkeys

18. Can I use a passkey instead of the authenticator app?

Yes. A passkey (Face ID, Touch ID, Windows Hello or a security key) is a second factor on its own. You can have passkeys only, an authenticator app only, or both. Everywhere Mirox asks for a second factor, a passkey counts: for the device proxy, for the plants of an organization that requires 2FA, and for creating API tokens. You add a passkey on the Security tab of your profile; if your account has no 2FA yet, you confirm with your password. With a passkey you can also sign in without a password: choose Sign in with a passkey on the sign-in page. See Passkeys.

19. I lost my passkey. What now?

If you still have your authenticator app, sign in with password and code as usual, and remove the lost passkey from your profile. If a passkey was your only second factor: sign in with your password, choose Send a code by e-mail on the code screen and enter the 6-digit code from the e-mail. Then add a new passkey or enable an authenticator app on the Security tab. Nobody has to unlock you. The e-mail code is only offered to accounts without an authenticator app; accounts with one use the backup code (question 7).

20. Why does the app ask for an e-mail code?

Because your only second factor is a passkey, and the device you are on does not have it, or because it is the mobile app, which does not sign in with passkeys yet. Mirox then sends a one-time 6-digit code to your account's e-mail address. It is valid for a short time, only one code is active at a time, and a wrong code counts like a wrong password (question 9). Enter the code and you are signed in. The next app update brings passkey sign-in to the mobile app. Accounts with an authenticator app never get the e-mail code.

Related Features

  • Authentication — sign-in, 2FA, how long a sign-in lasts and what you see when it ends
  • Organization Security Policy — the rules an organization can set, and what they do not affect
  • Setting Up Two-Factor Authentication — enable 2FA and keep your backup code safe
  • Managing Your Sessions — see your sign-ins and sign out other sessions
  • Account Temporarily Locked — what happens after too many wrong attempts
  • Remote Access FAQ — questions on the VPN and the device proxy
Prev
Remote Access — Frequently Asked Questions
Next
AI in Mirox — Frequently Asked Questions
© 2026 Mirox Verwaltungs GmbH. All rights reserved. | Privacy Policy