Requiring two-factor for your whole team
Force every staff member to set up two-factor authentication, with a grace period to enroll before it's required.
Where to find it
Settings → Security → Team MFA policy section
Team MFA policy lets an Owner require every staff member to set up two-factor authentication (a code from an authenticator app, in addition to their password), rather than leaving it optional per person.
Where to find it
Settings → Security → Team MFA policy section.
The Team MFA policy section with the Require two-factor auth setting
How it works
- Require two-factor auth — set to "Optional" by default. Only an Owner can change this. Switching it to "Required" forces every staff member to set up two-factor.
- Grace period — a read-only display of how many days staff have to enroll once the policy is set to Required. This defaults to 14 days.
Example
If you switch Require two-factor auth to "Required," every staff member sees a prompt to set up two-factor authentication and has 14 days to complete it before they're required to before logging in again.
Good to know
- Individual staff can still set up their own two-factor authentication voluntarily even while this policy is Optional.
- The grace period here is fixed at 14 days and is shown for information only — it isn't a field you can edit.
Still stuck? Ask the chat.