Skip to main content

How To Set Up 2FA With Microsoft For TV Dashboards

How to turn on two-step verification with an authenticator app in Microsoft, get your Secret Key, and connect a Microsoft-signed-in dashboard to Fugo's TV Dashboards feature.

Written by Sarah

Table of contents


If the dashboard, report, or URL you want to display on screen is protected behind a Microsoft sign-in - and that account has two-step verification turned on - Fugo needs a way to get past that verification step on its own, every time it refreshes your screen. That's what this guide walks you through.

A naming note before we start: Microsoft's own documentation calls this Microsoft Entra ID (its current name for what used to be called Azure Active Directory), and Fugo's sign-in method picker just calls it Microsoft. They're the same thing. This guide covers the everyday case - a Microsoft or work account with two-step verification turned on.

If you're a Microsoft Entra administrator managing sign-in policy for an entire organization, your conditional access and MFA setup happens in the Entra admin center rather than the personal account settings below, though the Secret Key concept Fugo needs is the same either way.

This guide covers two things: how to configure two-step verification on the Microsoft Account side so Fugo can use it (steps that live entirely inside Microsoft's own settings, not Fugo's), and how to hand Fugo what it needs when you set up the dashboard.

What you'll need

  • The email address and password for the Microsoft Account you want your dashboard to sign in with. We'd recommend a dedicated account for this rather than someone's personal or work login, so access doesn't disappear the day that person changes their password or leaves the company - but a personal account works too if that's what the dashboard already uses.

  • Two-step verification turned on for that account, with an authenticator app configured as the method - covered in Part 1 below.

  • The Secret Key Microsoft gives you while setting up that authenticator app - also covered in Part 1. This is the piece Fugo actually needs; you'll enter it once when you create the dashboard.

  • A dashboard, report, or URL that offers sign-in with a Microsoft account.


Why Fugo needs your Secret Key, not just a passcode

A quick bit of context before you start, because it explains everything that follows.

Fugo doesn't keep a browser open and watching your dashboard all day. Instead, on a schedule you control, it opens the page fresh, signs in, takes a screenshot, and closes again - with nobody sitting there to click anything. That works fine for a plain email and password. It breaks the moment your Microsoft Account asks for a second factor, because most 2FA methods need a human in the loop: approving a sign-in request notification, answering a phone call, reading a text message, or clicking "Yes" on a "Stay signed in?" prompt that happens to also be gating access. None of those can happen unattended.

An authenticator app is the one method that doesn't need a person - because the 6-digit code it shows you isn't random. It's generated from a shared Secret Key that both your phone's app and Microsoft's servers know, combined with the current time. Anyone holding that Secret Key can generate the same valid code Microsoft is expecting, at any moment, without a phone in hand. That's exactly what Fugo does: you give it your Secret Key once, and from then on it generates a fresh code itself, every single time it needs to sign in - the same way your authenticator app would, just running in the cloud instead of your pocket.

One difference worth knowing about up front if you've also set this up with a Google Account: Fugo has some built-in logic for navigating past alternate verification screens on Google, but nothing provider-specific for Microsoft. In practice that means the authenticator-app code needs to be the method Microsoft actually shows Fugo, not a fallback buried behind a "try another way" style link - covered in more detail in Keep the Authenticator app as your account's go-to method below.


Part 1: Set up 2FA in your Microsoft Account

These steps all happen on Microsoft's side, inside your Microsoft Account settings - Fugo has no control over this part of the process, so if Microsoft changes their layout after this article is published, the exact screens below may drift slightly even though the overall steps stay the same.

Turn on Two-step verification

If your account doesn't have two-step verification on yet, start here. If it's already on and you just need to add or re-generate an authenticator app entry, skip ahead to I already have the Authenticator app, but not my Secret Key.

1. Go to your Microsoft account Security page and open Advanced security options.

2. In the Additional security section, turn on Two-step verification. Click Next on the page that follows to continue.

Two-step verification is now on. By default Microsoft may still offer other methods first though - the next section replaces those with an authenticator app, which is the method Fugo can actually use.

Set up the Authenticator app and get your Secret Key

3. Under Verify my identity with, choose An app, then click Set up a different authenticator app (rather than accepting push approval through Microsoft's own Authenticator app).

4. You'll land on a QR code screen. Don't scan it. Instead, click I can't scan the barcode to reveal the Secret Key as text.

5. Copy the Secret Key and save it somewhere secure right now - a password manager is ideal. You'll need it in a moment for Fugo.

6. Microsoft still needs to see the key work once before it'll accept the setup. If you have a spare phone or a browser-based authenticator handy, enter the Secret Key there to generate a 6-digit code.

7. Enter that code back into Microsoft's setup page to confirm.

8. Click Next to finish. You'll land back on the Security page, where you should see Two-step verification confirmed as On, and Enter a code from an authenticator app listed as Up to date.

You now have everything Part 2 needs: the account's email, password, and the Secret Key you saved in step 5.

I already have the Authenticator app, but not my Secret Key

If two-step verification is already on and an authenticator app is already listed as a method, most authenticator apps don't let you view a key after the fact - so the simplest path is to remove that method and add it again, capturing the key this time. From your Microsoft account Security page, open Advanced security options, find the existing authenticator app entry, and remove it.

That drops you back into Set up the Authenticator app and get your Secret Key above, where I can't scan the barcode reveals a fresh Secret Key. This replaces the old one - your authenticator app will need re-scanning too, so do this only when you're ready to update both places at once.

Keep the Authenticator app as your account's go-to method

Unlike some providers, Fugo doesn't have Microsoft-specific logic for clicking through an alternate-method chooser if the authenticator app isn't the method Microsoft shows by default. If your account still offers "Approve a sign-in request" push notifications, a phone call, or a text message ahead of the authenticator app, Fugo can get stuck waiting on a screen it has no way to answer.

A couple of things worth doing on this same Microsoft Account:

Remove other verification methods - push approval, phone call, text message. Once the authenticator app is confirmed working (Part 1 above), go back into your account's verification methods and remove anything else, so a password plus an authenticator-app code is the only thing standing between Fugo and a signed-in session.

Don't worry about "Stay signed in?" Fugo automatically detects and clicks through Microsoft's "Stay signed in?" (sometimes shown as "Skip 2FA next time on this device") prompt after a successful sign-in, so this one isn't something you need to disable - it's handled either way.

Consider disabling email alerts on the account. You won't want a notification every time Fugo signs in on schedule.

You're ready to head over to Fugo.


Part 2: Connect your Microsoft-authenticated dashboard in Fugo

With two-step verification on and your Secret Key saved, the Fugo side is a short form - there's no live sign-in to click through and nothing to record. You give Fugo your Microsoft credentials and Secret Key once, and it signs in on its own from then on, on whatever refresh schedule you set.

Create a new dashboard

1. From the Dashboards page in Fugo CMS, click Create dashboard.

You'll see a browsable list of services with automated sign-in built in - a couple of these (currently HubSpot and allGood) already offer Microsoft as one of their one-click sign-in options, so if your dashboard lives in one of those, you can pick its card directly.

For anything else - any other site or dashboard that offers a Microsoft sign-in - choose the Custom URL card, pinned at the top of the list. It works the same way for any Microsoft-authenticated site, not just the ones with their own dedicated card.

Tableau is a special case - its card has its own dedicated Sign in with Azure option, separate from the general Microsoft method described here. See our Tableau guide if that's what you're connecting.

Choose Microsoft as the sign-in method

If you picked a named service (like HubSpot), you'll see its available sign-in methods as buttons - choose Sign in with Microsoft.

If you picked Custom URL, enter the destination URL first (the page you actually want on screen, not a Microsoft URL), then use the Authentication Method dropdown to select Microsoft.

Enter your Microsoft account details and Secret Key

The form will now ask for:

  • Username. The full email address of the Microsoft Account from Part 1 - not a username or login for the destination site itself, since you're authenticating through Microsoft.

  • Password. That Microsoft Account's password.

  • Secret Key. The key you copied in step 5 of Part 1. Paste it exactly as Microsoft displayed it, with no extra spaces. This field is what lets Fugo generate its own 2FA codes going forward; if you leave it blank, Fugo will get stuck at Microsoft's verification screen every time it tries to refresh your dashboard.

Fugo encrypts and securely stores whatever you enter here - it's used only to sign in on your behalf when this dashboard refreshes.

Click Create dashboard when you're done.

What happens when Fugo captures your dashboard

There's nothing left for you to watch. On the schedule you've set for this dashboard, Fugo opens the destination URL in the background, clicks through to Microsoft, enters your email and password, generates a fresh code from your Secret Key the moment Microsoft asks for it, and takes a screenshot once the page has loaded - all without a browser window ever appearing on your screen.

If you've used Fugo dashboards before and remember a "Dashboard Recorder" window popping up for you to click through a live sign-in, that step is gone for Microsoft-authenticated dashboards; entering the Secret Key up front is what replaced it.


Finding or updating the 2FA step later

Once your dashboard is created, open it and go to the Home tab, and find the Steps list. You'll see the login sequence Fugo runs on every refresh, including a step labeled something like Pass 2FA - that's the Secret Key you entered:

If you ever remove and re-add the authenticator app on this Microsoft Account (which issues a new Secret Key, per Part 1), your dashboard will start failing to sign in until you update it here too. Click the pencil icon next to the 2FA step, paste in the new Secret Key, and save - there's no need to recreate the dashboard from scratch.


Troubleshooting

If your dashboard's screenshots stop updating or show a login/verification screen instead of your content, a few things are worth checking:

Make sure the authenticator app is the method Microsoft shows first. Fugo doesn't have Microsoft-specific logic for navigating past a push-approval or phone prompt to reach the code entry screen the way it can for some other providers. If any other method got re-added to the account, remove it so the authenticator-app code is what Microsoft asks for.

Double-check the Secret Key was copied correctly. It's easy to miss a character or leave a stray space in when copying it. Re-open the key from Microsoft (you'll need to remove and re-add the authenticator app method, per above, since Microsoft won't show you an existing key) and re-enter it on the dashboard's Steps tab.

Check whether the account password changed. If it was updated outside of Fugo, update it on the dashboard's Steps tab the same way you would the Secret Key.

Still stuck? Our dashboards team can take a look - reach us via the chat box in Fugo CMS or at support@fugo.ai.


More guidance connecting your dashboard

Fugo can be used to access just about any dashboard, report, or URL living behind a secure login. A few of our most-used services have their own dedicated setup guides:

For everything else, browse the Dashboards Overview, or reach out and our dashboards team will help you get it connected.


Need more help?

Reach us any time via the chat box in Fugo CMS, or at support@fugo.ai.

And if you haven't yet, you can always try Fugo free at www.fugo.ai/app.

Did this answer your question?