Sign in
Signing in with an email address or your company account (SSO), the second factor, and how long a session lasts.
With your email address
Open your console's address (your administrator will have given it to you), enter your Email and Password, then click Sign In. If your account uses two-factor authentication, the Two-factor verification screen follows (see below).
An unknown address and a wrong password produce the same message, "Invalid credentials". That is deliberate: the screen never tells you which of the two is wrong.
With your company account (SSO)
If your organisation has connected its company sign-in (Microsoft Entra ID, Okta, Google Workspace or any OpenID Connect provider), a Se connecter avec … button (sign in with …) appears as soon as you have typed your address. It takes you to your company's usual sign-in page and then brings you back to FirstSI.
On the way back you may see one of these messages:
| Message | Meaning |
|---|---|
| Your email domain is not allowed | Your address is not in the domains your administrator declared |
| User not found. Contact your administrator. | You have no FirstSI account and automatic creation is turned off |
| Your account is disabled | An administrator has disabled your FirstSI account |
| Session expired, please try again | The round trip through your company's page took too long; start again |
The second factor
Depending on what you set up under Two-factor authentication, you have three options:
- Use my security key: touch the key (YubiKey…) or confirm with Windows Hello or Touch ID;
- the 6-digit code shown by your authenticator app;
- Use a backup code: one of the 10 codes handed out when you turned the feature on, in the form
XXXX-XXXX-XXXX. Each one works only once. See I lost my phone.
Too many attempts
After 5 attempts in 15 minutes for the same email address from the same computer, sign-in is refused for the time shown on screen. The second factor has its own counter with the same rule. Just wait; there is no need to call an administrator.
Your session
Once you are signed in, your session renews itself as long as you keep using the console, for up to 7 days.
Your organisation may also enforce automatic sign-out after inactivity. A minute before it happens, a warning offers Stay signed in. Only mouse, keyboard, scrolling and touch count as activity: a screen that refreshes on its own does not keep you signed in.
All your sessions are closed when you change your password, or when an administrator resets it, changes your role or disables your account.
Change your password
Go to Settings → Profile (or Security), section Change password. The new password must be at least 12 characters long, with an upper-case letter, a lower-case letter, a digit and a special character.
If you have forgotten it, an administrator in your organisation can reset it from Settings → Users. See also I can't sign in.
Source: · FirstSI Docs · updated 2026-10-10