Guide · People and groups

Require two-factor authentication for collaborators

Make two-factor authentication mandatory for every collaborator or only for leadership roles, and check who still needs to turn it on.

2 minVerified on 26 Sept 2026Leaders and office staffAvailable

Before you begin

  • You need the Manage two-factor authentication permission.
Section 1

Make it mandatory for everyone

In Settings open Staff security. The Two-factor authentication box explains the current state; turn on Require for everyone to make it mandatory for every collaborator. 2FA now required for all collaborators appears.

Fig. 1Besides the password, a code from the phone will be needed.
Section 2

Check who is missing

Below the switch the bar shows how many collaborators already turned it on, for example 3/5 already active, and Without 2FA: lists who still has to. When everyone complies, All collaborators have enabled 2FA. appears.

Fig. 2Follow up in person with anyone on the list.
Section 3

Leadership roles only

In Team Security the Require 2FA for all leadership roles switch limits the requirement to leadership roles. When you turn it on, choose the Grace period (7 days, 14 days or 30 days) and follow the Compliance Status.

Anyone who must set it up sees the Two-factor authentication required notice with the date to do it by.

Fig. 3The grace period leaves time to set it up.

What you have achieved

  • From now on the collaborators concerned must confirm sign-in with a code from their phone.
  • You can see at any time who hasn’t turned it on yet.

Troubleshooting

I see “Unable to verify collaborators' 2FA status right now. Try again later.”

The status is unavailable and the switch is locked: try again later.

I can’t see Staff security

You are missing the Manage two-factor authentication permission.

What happens after the grace period?

Anyone who hasn’t set it up sees “The grace period has expired” and must set up 2FA to keep accessing all features.