Beskos

Administration

Require two-factor authentication

Enforcing two-factor authentication across an organisation.

Updated:

Contents

Two-factor authentication can be configured as optional or mandatory. When mandatory, a user without a configured second factor is required to complete enrolment before proceeding.

Supported methods

An authenticator application (TOTP) or a code delivered by SMS. Both methods may be permitted, or one may be required.

Enabling the requirement

Administration → Security. The requirement applies immediately, including to users with active sessions.

Recovery codes

Enrolment generates recovery codes, displayed once. They provide access if the second factor becomes unavailable and must be stored at that point. An administrator can reset a user's second factor; the codes cannot be displayed again.