Settingsbeginner

Require two-factor authentication

Workspace owners can turn on a policy requiring two-factor authentication for all users or for specific roles. The change applies immediately — covered users enrol in the web app, and every sign-in after that, including the mobile app and API password sign-in, asks for their authenticator code — and is logged as a security event.

3 min read

Require two-factor authentication

Owners can require two-factor authentication (2FA) for everyone in the workspace, or just for certain roles — Owners, Team leads, or Everyone else. Once turned on, the requirement applies right away: covered users are asked to set up an authenticator app in the web app, and every sign-in after that — web, mobile app or API password sign-in — asks for a code from it.

Who can do this

Only workspace owners can view and change this setting. It doesn’t appear for admins or members, even if they otherwise have broad permissions — this is a deliberate exception so that enforcing 2FA can’t be relaxed by anyone other than an owner.

Turning it on

  1. Go to Settings → Administration → 2FA.
  2. Switch on Enabled. It’s off by default. Confirming with Turn it on applies the requirement.
  3. Under Who it applies to, everyone is covered to begin with. Untick Owners, Team leads or Everyone else to narrow it, or tick all three to go back to covering everyone.

There’s no separate “Save” step — apart from that one confirmation when you first turn it on, each change is applied straight away.

What happens for covered users

As soon as a user falls under the policy — either because every role is covered or because their role is ticked — they’re asked to set up an authenticator app or verify with their existing second factor the next time they make a request to the workspace in the web app. There’s no delay for a cache to catch up; the change is live immediately.

Enrolment itself only happens in the web app. A covered user who hasn’t enrolled yet is turned away from the mobile app and from API password sign-in with 403 MFA_ENROLLMENT_REQUIRED until they have set up their authenticator in the web app. Once enrolled, those sign-ins answer with an MFA challenge (mfaRequired: true) and complete with the authenticator code. A mobile or API session that was opened without a second factor — for example one from before the requirement was turned on — is refused with 403 MFA_REQUIRED until the user signs in again.

Users who aren’t covered (for example, Everyone else when the policy is scoped to Owners and Team leads only) aren’t affected and won’t see an enrolment prompt.

Scoping to specific roles

When you turn the requirement on, the roles list starts with Owners, Team leads and Everyone else all selected — everyone is covered — rather than nobody, since an empty role list means every role is covered.

You can then turn individual roles on or off:

  • Turning a role on means anyone with that role must have 2FA enrolled.
  • Turning a role off removes that role from the requirement.

If you turn off the last remaining role, the two-factor requirement is switched off entirely rather than silently expanding to cover everyone. If you want it to cover everyone, tick all three roles instead of leaving the role list empty.

Turning it off

Switch Enabled back off. This removes the requirement for every role immediately — no one is prompted to enrol going forward, though anyone who already set up 2FA keeps it enabled on their own account unless they remove it themselves.

Audit trail

Every change to this policy — turning it on or off, and any change to which roles are covered — is recorded as a security event, along with the owner who made the change. Use this to confirm when 2FA enforcement was enabled, narrowed, widened, or removed, and by whom.

Things to know

  • This is a tenant-level policy — it’s set per workspace, not per user.
  • Only owners can view or change it; it won’t show up in the Settings navigation for other roles.
  • The change is immediate. There’s no rollout delay or grace period built into the setting itself — plan communication to your team before turning it on if you want to give people advance notice to install an authenticator app.

Tags

How ToSecurity