Requiring two-factor for your whole team

Force every staff member to set up two-factor authentication, with a grace period to enroll before it's required.

Where to find it

Settings → Security → Team MFA policy section

Team MFA policy lets an Owner require every staff member to set up two-factor authentication (a code from an authenticator app, in addition to their password), rather than leaving it optional per person.

Where to find it

Settings → Security → Team MFA policy section.

The Team MFA policy section with the Require two-factor auth settingThe Team MFA policy section with the Require two-factor auth setting

How it works

  • Require two-factor auth — set to "Optional" by default. Only an Owner can change this. Switching it to "Required" forces every staff member to set up two-factor.
  • Grace period — a read-only display of how many days staff have to enroll once the policy is set to Required. This defaults to 14 days.

Example

If you switch Require two-factor auth to "Required," every staff member sees a prompt to set up two-factor authentication and has 14 days to complete it before they're required to before logging in again.

Good to know

  • Individual staff can still set up their own two-factor authentication voluntarily even while this policy is Optional.
  • The grace period here is fixed at 14 days and is shown for information only — it isn't a field you can edit.

Still stuck? Ask the chat.