Skip to content
English
  • There are no suggestions because the search field is empty.

Enabling Two-Factor Authentication (2FA)

Add an extra layer of security to protect your account and your team's data

Two-Factor Authentication adds an extra layer of security to your account. When enabled, users must enter a verification code from their phone in addition to their password when logging in. This protects against unauthorized access even if a password is compromised.

Enabling 2FA for Your Organization

  1. Go to Admin > Settings > Security.
  2. Toggle Two-Factor Authentication to On.
  3. Choose the enforcement level:
    • Required for all users — Every user must set up 2FA on their next login. No one can skip it.
    • Optional — Users can choose to enable 2FA themselves from their profile settings.
  4. Click Save.

How Users Set Up 2FA

  1. Download an authenticator app — Google Authenticator, Authy, or Microsoft Authenticator all work.
  2. On the next login, a QR code appears on screen. Scan it with the authenticator app.
  3. Enter the 6-digit verification code from the app to confirm the pairing.
  4. Save the backup recovery codes in a secure location — you'll need these if you lose access to your phone.

If a User Loses Access

If a user loses their phone or can't access their authenticator app:

  • They can use a backup recovery code to log in.
  • If they've lost their recovery codes too, an admin can reset their 2FA from Admin > Manage Users > click the user. The user will be prompted to set up 2FA again on their next login.
Recommendation: For firms handling sensitive client data — especially legal, financial, and healthcare — requiring 2FA for all users is a best practice.