Administration
Require two-factor authentication
Enforcing two-factor authentication across an organisation.
Updated:
Two-factor authentication can be configured as optional or mandatory. When mandatory, a user without a configured second factor is required to complete enrolment before proceeding.
Supported methods
An authenticator application (TOTP) or a code delivered by SMS. Both methods may be permitted, or one may be required.
Enabling the requirement
Administration → Security. The requirement applies immediately, including to users with active sessions.
Recovery codes
Enrolment generates recovery codes, displayed once. They provide access if the second factor becomes unavailable and must be stored at that point. An administrator can reset a user's second factor; the codes cannot be displayed again.