Lesson Account profile and security

Sign-in Approval: A secure and convenient way to protect your account

Sign-in Approval is Questrade's most secure and convenient verification method, allowing you to approve or deny login attempts directly from your designated Primary Trusted Device. It provides real-time, context-rich notifications—including device type, time, and login location on a mini-map—to help you identify and block unauthorized access instantly. Plus, it’s travel-ready: access your account on Wi-Fi globally without needing a local SIM.

Why is it more secure?

SMS and email codes can be intercepted, forwarded, or phished — an attacker who has your password and your phone number may still be able to get in. Sign-in Approval works differently: the approval happens inside the Questrade app itself, and the notification goes only to your Primary Trusted Device. Even if an attacker has your credentials, they cannot approve the login without physical access to your Primary Trusted Device (e.g., your phone).


What you see on the approval screen

What it protects against

Device type, approximate location, and timestamp for every login attempt

Lets you identify logins you did not initiate, even if the attacker has your password.
Note: Location is IP-based geolocation, not GPS. It can be off by a few kilometers or more depending on your carrier, network routing, or if you are on a VPN.

Approval happens inside the Questrade app, not via SMS or email

Prevents interception and phishing — attackers cannot redirect or replicate an in-app approval

 

Getting started: How to enroll your device

Enrolling your device for Sign-in Approval is a simple process that can be done in two ways.

    1. Enroll when you log in
      • Update your QuestMobile or Edge Mobile application to the latest version.
        (You can download our mobile apps here: QuestMobile or Edge Mobile)
      • Simply enroll your device when prompted upon logging into the app.
        • If you’re not ready, you can select Remind me later.
    2. Enroll in the Security Center
      • Update your QuestMobile or Edge Mobile app to the latest version.
      • From your mobile app, select Settings > Security Centre.
      • Select the Sign-in Approval setting and toggle it ON. This will enroll the device you’re currently using.

How it works

  1. Log in as usual

    Enter your username and password on the Questrade website or another device as you normally would.

  2. Receive a notification

    A push notification will be sent instantly and exclusively to your one designated Primary Trusted Device.

  3. Review the details

    Tapping the notification opens a screen in your Questrade app where you can review the critical login details. You’ll need to unlock your phone to check the notification details. You will see:

    • Device: what browser and OS initiated the login (e.g., Windows 11, Chrome 134)
    • Where: an approximate location based on IP address, shown on a mini-map (e.g., Near Quebec City, Quebec)
    • When: timestamp of the login attempt (e.g., May 12, 2026 at 1:53 p.m. ET)

    The request expires after 3 minutes. If you do not respond in time, the login attempt fails and you will need to start again or use another MFA method.

  4. Approve or Deny
    • If the details match your login attempt, tap Allow.
    • If you don't recognize the activity, tap Don't Allow to immediately block the attempt.

 

If the notification does not arrive, tap Resend notification to send another notification. If you need to log in immediately, tap Try another way to use SMS, Voice, or an authenticator app instead.

Managing your Sign-in Approval settings

You can manage your Sign-in Approval preferences easily from the Security Center. Here are the main actions you can take:

  • Changing your Primary Trusted Device: Only one mobile device can be your designated Primary Trusted Device at a time.
  • Disabling Sign-in Approval: If you wish to turn the feature off, you can return to the Security Center at any time and toggle it OFF. Your other MFA methods (SMS/Voice, authenticator app) remain available.

Frequently Asked Questions (FAQ)

  1. What if I do not receive the Sign-in Approval notification? First check that push notifications are enabled for the Questrade app in your phone settings. If they are, tap Resend notification on the waiting screen to try again. You can also tap Try another way to use SMS, Voice, or an authenticator app.
  2. What if the request times out? Sign-in approval requests expire after 3 minutes. If yours timed out, restart the login process. You can use another MFA method if you need to get in immediately.
  3. Will my other MFA methods be disabled? No. SMS/Voice and authenticator apps remain available as alternatives. Note: email-based MFA is being phased out.
  4. What if I do not use QuestMobile or Edge Mobile? Sign-in Approval requires the mobile app. If you do not use it, your existing MFA methods are unchanged.
  5. What if I get a new phone? Log in on your new device using your old phone or a backup MFA method (e.g., SMS). Once logged in, go to Settings > Security Centre, disable Sign-in Approval on the old device, and re-enroll your new phone as your Primary Trusted Device.
  6. Why does the location look wrong? Location is based on IP address geolocation, not GPS. It can be off by a few kilometers or more depending on your carrier, network routing, or if you are on a VPN. If the device type and timestamp look right, the login is likely yours.

 

The Questrade Security Team

Note: The information in this blog is for educational purposes only and should not be used or construed as financial or investment advice by any individual. Information obtained from third parties is believed to be reliable, but no representations or warranty, expressed or implied, is made by Questrade, Inc., its affiliates or any other person to its accuracy.

Related lessons

Want to dive deeper?

Read next

Explore

Have more questions?

Tell us what you need help with, and we’ll get you in touch with the right specialist.