---
title: Cross River access troubleshooting
slug: ops-and-admin/org-management-portal/access-troubleshooting
description: Troubleshoot COS Explorer access issues including firewall restrictions, MFA code errors, password resets, and account lockouts.
docTags: 
createdAt: 2025-08-25T11:33:49.100Z
---

When logging in to a Cross River application, there are some common issues that might crop up.&#x20;

## Site cannot be reached

If you log in to a Cross River application for which you have access and get following error screen, you are blocked by the firewall.

![](https://api.archbee.com/api/optimize/Qt8sSSvJnFaDir3Z-GD2j-Kc3YWS0Zb310IMKY0uVt--20250123-122443.png)

To unblock your access:

1.   Contact your internal IT department to see if your organization enforces firewall rules for outbound traffic. If they do, ensure that your access to the application is not blocked.
2.   If there are no firewall rules for outbound traffic, contact your internal IT department to make sure you're connecting to the Cross River application portal from an approved IP address. If you need to register more IP addresses, send an email to [customer.support@crossriver.com](mailto\:customer.support@crossriver.com).

## Multifactor authentication

### Invalid MFA code

If you enter an invalid MFA code, a red message under the code field asks you to try again. A code could be invalid because:

- **Code timeout**
  If the code timed out before you clicked **Continue** (and is therefore invalid), you need to generate a new code. Some authenticator apps indicate the time remaining for the code to be valid by showing a countdown circle to the right of the account name and MFA code.
- **Wrong code**
  If you have the authenticator app set up for multiple Cross River environments or applications, double check that you entered the correct code for the application you are entering.

:::hint{type="info"}
If you are using the authentication app for more than one environment or application, we recommend that you give a meaningful name to each MFA connection.
:::

### Reset multifactor authentication

If you already have MFA configured:

1. Log in to [https://idptest.crbcos.com/](https://idptest.crbcos.com/)**.&#x20;**
2. Click **Account settings**.
3. Click **Reset your MFA device**.

If your current MFA is SMS, you can enable MFA with your authenticator app.

### Reset MFA if you change phones

If you need to use a new device:

1. Download the authenticator app to your new phone.
2. Log in to the Cross River application and authenticate using your old phone.
3. Create a new user for your new phone. If you can't create a user or if you don't succeed in authenticating with your new phone, ask your organization admin to reset the MFA. You'll go through the initial [access process](docId\:JwSEUG3ELF_gXLhy6T9KI) again.

If you lose your phone you'll need to [authenticate with a recovery code](docId\:WJspnXy9wpWu5rlxVOHyp) and then reset your MFA for your new phone.

### Create new recovery codes

You can also create new multifactor authentication recovery codes from the reset screen. Note that you are only allowed to create new recovery codes 10 times.

1. Click **create new multi-factor authentication recovery codes**.
2. The Recovery Codes page opens and you can copy or download your 10 new recovery codes.

### Use a recovery code

If you do not have access to your multifactor (2-factor) authenticator, you can log in using one of your recovery codes.

1. Log in as usual.
2. On the multifactor authentication page, select the option to use a recovery code as your authentication option.
3. Enter one of your recovery codes in the text box. Once you've used it, the recovery code cannot be reused. To avoid future confusion, we recommend that you mark the recovery code as used.

## Forgot password

1. In the login screen, click **Forgot password?** and enter your email.
2. Generate a 6-digit authentication code from your authenticator app and enter it in the field.
3. We send you a *Forgot Password* email. Click **Reset Password** in the body of the email.
4. In the Password Reset page that opens, enter a new password, click **Reset Password**, and **Continue to the application**.

## Account lockout

If you enter the wrong password for your username 5 times, the system locks your account for approximately 5 minutes. If after 5 minutes, you are still unable to access your account, contact [customer.support@crossriver.com](mailto\:customer.support@crossriver.com).

