Enabling Two-Factor Authentication (2FA)
Add an extra layer of security to protect your account and your team's data
Two-Factor Authentication adds an extra layer of security to your account. When enabled, users must enter a verification code from their phone in addition to their password when logging in. This protects against unauthorized access even if a password is compromised.
Enabling 2FA for Your Organization
- Go to Admin > Settings > Security.
- Toggle Two-Factor Authentication to On.
- Choose the enforcement level:
- Required for all users — Every user must set up 2FA on their next login. No one can skip it.
- Optional — Users can choose to enable 2FA themselves from their profile settings.
- Click Save.
How Users Set Up 2FA
- Download an authenticator app — Google Authenticator, Authy, or Microsoft Authenticator all work.
- On the next login, a QR code appears on screen. Scan it with the authenticator app.
- Enter the 6-digit verification code from the app to confirm the pairing.
- Save the backup recovery codes in a secure location — you'll need these if you lose access to your phone.
If a User Loses Access
If a user loses their phone or can't access their authenticator app:
- They can use a backup recovery code to log in.
- If they've lost their recovery codes too, an admin can reset their 2FA from Admin > Manage Users > click the user. The user will be prompted to set up 2FA again on their next login.
Recommendation: For firms handling sensitive client data — especially legal, financial, and healthcare — requiring 2FA for all users is a best practice.