Require two-factor authentication for collaborators
Make two-factor authentication mandatory for every collaborator or only for leadership roles, and check who still needs to turn it on.
Before you begin
- You need the Manage two-factor authentication permission.
Make it mandatory for everyone
In Settings open Staff security. The Two-factor authentication box explains the current state; turn on Require for everyone to make it mandatory for every collaborator. 2FA now required for all collaborators appears.
Check who is missing
Below the switch the bar shows how many collaborators already turned it on, for example 3/5 already active, and Without 2FA: lists who still has to. When everyone complies, All collaborators have enabled 2FA. appears.
Leadership roles only
In Team Security the Require 2FA for all leadership roles switch limits the requirement to leadership roles. When you turn it on, choose the Grace period (7 days, 14 days or 30 days) and follow the Compliance Status.
Anyone who must set it up sees the Two-factor authentication required notice with the date to do it by.
What you have achieved
- From now on the collaborators concerned must confirm sign-in with a code from their phone.
- You can see at any time who hasn’t turned it on yet.
Troubleshooting
I see “Unable to verify collaborators' 2FA status right now. Try again later.”
The status is unavailable and the switch is locked: try again later.
I can’t see Staff security
You are missing the Manage two-factor authentication permission.
What happens after the grace period?
Anyone who hasn’t set it up sees “The grace period has expired” and must set up 2FA to keep accessing all features.