Your Graphisoft ID is the account you use to access Graphisoft products, services, licenses, and company resources. Protecting it helps prevent unauthorized access, unwanted account changes, and interruptions to the services your organization relies on.
This guide explains the practical steps you can take to strengthen your security. Apply these recommendations together with any policies required by your employer or IT administrator.
1. Create a strong password that you use only for Graphisoft ID
Password reuse is a common account-security risk. If another website is compromised and you used the same password there, an attacker may try those credentials on your Graphisoft ID. A unique password limits the effect of such an incident.
For your Graphisoft ID:
- Use a password that you do not use for any other account.
- Make it long and difficult to guess.
- Avoid names, dates, company details, common expressions, and predictable patterns.
- Never send your password by email, chat, or another communication channel.
- Change it immediately if you think it may have been exposed.
A reputable password manager can create and securely store complex passwords for you. This makes it easier to use a different password for every service without having to remember them all.
Examples include 1Password, Bitwarden, and the password managers built into Google Chrome, Microsoft Edge, Apple Safari, and Mozilla Firefox.
2. Enable Multi-Factor Authentication
Multi-Factor Authentication (MFA) adds an additional layer of security to your Graphisoft ID account; it helps protect your account even if your password becomes known to someone else.
After MFA is activated, signing in requires 2 steps:
- Your Graphisoft ID password
- A current verification code from your authenticator application
All major authenticator applications are supported. Common options include Microsoft Authenticator and Google Authenticator.
Please check our Support Site articles on MFA, as compatibility can vary depending on product version, authentication method, and license type.
3. Protect your authenticator device
Your authenticator device acts like a key to your account. If another person can unlock the device or view its verification codes, the protection provided by MFA is reduced.
To protect it:
- Use a PIN, password, biometric lock, or another secure screen lock.
- Keep the operating system and authenticator application up to date.
- Never reveal a verification code or generate one for another person.
- Do not approve sign-in requests that you did not initiate.
If your authenticator device is lost, stolen, replaced, or unavailable, your Graphisoft ID Company Administrator or Contract Manager can deactivate MFA for your account in the Company Management Portal. Graphisoft Support can also assist with that after verifying account ownership. After MFA is deactivated, remove the old account from the authenticator application and register it again before reactivating MFA.
4. Use an individual account - never share credentials
A Graphisoft ID is intended for one person. Shared accounts make it harder to identify who performed an action, increase the chance that credentials will be exposed, and complicate access removal when responsibilities change.
Always:
- Use your own Graphisoft ID.
- Keep your credentials private, including from colleagues and external partners.
Individual accounts improve security, accountability, and the protection of company data and licenses.
5. Reset your password safely when needed
Use the official password-reset page if you forget your password or believe that your account may be at risk:
Reset your password immediately when:
- You notice unfamiliar or suspicious activity.
- You learn that the same credentials may have appeared in a data exposure.
- You entered your password on a suspicious or incorrectly spelled website.
- Graphisoft notifies you that a password reset is required.
Choose a new password that has not been used anywhere else. If you reused the affected password on another service, change it there as well.
Why Graphisoft may require a password change
Graphisoft may invalidate a password as a precaution, for example when security monitoring identifies unusual activity or when an account has been inactive for an extended period.
If your password has been invalidated, follow the instructions in the notification or use the official “Forgot password?” option to set a new password.
6. Check the address before you sign in
Before entering your email address, password, or MFA code, confirm that you are on the official Graphisoft ID website: https://id.graphisoft.com
Fraudulent websites may imitate Graphisoft pages and use an address with a small spelling change, an added word, or a different domain (known as typosquatting) to steal usernames, passwords, or MFA codes.
Before entering your credentials:
- Read the complete address in your browser’s address bar.
- Confirm that it is exactly https://id.graphisoft.com.
- If a link in an email or message looks unusual, do not use it. Open the known Graphisoft ID address yourself instead.
7. Recognize phishing and suspicious messages
Phishing messages try to create urgency or appear trustworthy so that you reveal credentials, open a harmful attachment, or visit a fraudulent sign-in page.
Warning signs include:
- An unexpected request to sign in, or provide account information.
- A demand for your password or MFA verification code.
- Pressure to act immediately or a threat that access will be removed.
- A sender address or destination website that does not match the expected domain.
- Unexpected attachments or unusual wording.
Legitimate Graphisoft communications are sent from Graphisoft-managed domains (@graphisoft.com).
Graphisoft will never ask you to send your password or MFA code by email.
8. Act quickly after a suspicious sign-in or link
If you entered your credentials on a suspicious page, disclosed an MFA code, or notice unfamiliar account activity, take these steps without delay:
- Reset your Graphisoft ID password at https://id.graphisoft.com/user/forgot/password.
- Change the password on any other account where you used the same or a similar password.
- Review the security of your authenticator device and reconfigure MFA if necessary.
- Contact Graphisoft Support if you believe that your account, licenses, or company access may have been affected.
Do not wait for confirmation of misuse. Prompt action can limit the impact of exposed credentials.
9. Keep your devices secure
Account security also depends on the computers and mobile devices used to access Graphisoft products and services. A compromised or unattended device may expose an active session even when your password is strong.
Recommended practices:
- Keep your operating system and browser updated.
- Install security updates regularly.
- Avoid signing in on public, unknown, or shared devices.
- Do not store passwords in unprotected notes or files.
10. Contact Graphisoft when you need help
Contact Graphisoft Support if you cannot access your account, notice suspicious account activity, or believe your Graphisoft ID, company access, licenses, or connected services may have been compromised.
Include enough information to help the support team investigate, such as:
- A clear description of what happened and when.
- The affected product or service and any error message shown.
- The steps that led to the issue.
- Screenshots with passwords, verification codes, and other sensitive information removed.
Never publish or send passwords, MFA codes, recovery information, or other sensitive authentication details.
Privacy and personal data
Graphisoft processes personal data connected with Graphisoft ID accounts in accordance with applicable privacy requirements. Review the current Graphisoft ID Terms of Use and Privacy Policy for information about how account-related data is handled and what rights may apply to you.
Quick security checklist
Use this checklist to review your Graphisoft ID security:
- Use a long, unique password or passphrase.
- Store passwords in a reputable password manager.
- Enable MFA and protect the authenticator device.
- Use only your own Graphisoft ID.
- Confirm that the sign-in address is [https://id.graphisoft.com](https://id.graphisoft.com).
- Treat unexpected sign-in and password-reset messages with caution.
- Reset exposed credentials immediately.
- Keep your devices updated.
- Contact Graphisoft Support when account security may be affected.
Make these practices part of your routine
Security is most effective when it becomes a habit. Using a unique password, enabling MFA, checking sign-in addresses, and keeping devices updated can significantly reduce the risk of unauthorized access to your Graphisoft account and connected resources.