CentralCSP
Security

Two-factor enforcement

Require every workspace member to have two-factor authentication. What happens to members who do not, and the one prerequisite before turning it on.

Last update:

Settings > General > Require two-factor authentication makes two-factor authentication mandatory for everyone in the workspace.

Workspace Admins and the Owner can change this setting.

Prerequisites

You cannot turn the requirement on without having two-factor authentication on your own account. The attempt is refused with a prompt to set it up first. For more information, refer to Two-factor authentication.

The switch also takes effect for everyone at once, including people who are asleep, on leave, or mid-deploy. Two things are worth doing first:

  • Tell people, with a date: Enrolment takes a minute, but only if they know it is coming.
  • Check your integrations: Anything running as a person who has not enrolled starts failing. API keys act as their creator, so a key created by an unenrolled member stops working. For more information, refer to API keys.

Turn on the requirement

In Settings > General, turn on Require two-factor authentication. It applies immediately.

What members without two-factor see

They cannot use this workspace until they enrol an authenticator app. They are not signed out, and their other workspaces are unaffected.

The block is total. API calls scoped to this workspace are refused the same way, so an unenrolled member's integrations stop working too.

Turn off the requirement

Flipping the switch back restores access for unenrolled members immediately. Nobody's existing two-factor authentication is removed.

Turning the requirement on and off is recorded in the audit log as workspace.mfa_enforcement_changed.

Next steps

On this page