Two-step verification
Two-step verification (also called two-factor authentication) requires users to confirm sign-ins with a one-time code in addition to their login and password. Depending on what is enabled on the platform, users can verify with an authenticator app, a code sent by email, or a code sent by text message (SMS).
Users enroll their own verification methods from My Profile › Security — see Account security in the User Guide. This page covers what administrators control: whether two-step verification is required, and for whom.
Managed by your service provider
The verification methods themselves (authenticator app, email, SMS) are enabled and configured at the platform level. If your portal shows "2-step verification is not configured on this system", the feature is not yet enabled — the enforcement settings below have no effect until your service provider enables at least one method.
Requiring two-step verification for your organization
The organization-wide policy lives in the Two factor authentication section of Administration › User Authentication › Password Policy. The 2-step verification setting has three options:
- Required for all users — every user must verify sign-ins with a second step.
- Required for non-SSO users — required for password sign-ins, but users who sign in with single sign-on are exempt (useful when your identity provider already enforces its own MFA).
- Not enforced — two-step verification is optional; users may still enroll methods voluntarily.
When verification is required, users who have not yet enrolled a method are taken through the enrollment wizard at their next sign-in.
Requiring two-step verification for individual users
Instead of an organization-wide requirement, you can require two-step verification per user: on the user's edit form, select Require 2-step verification for user login (see User accounts). Use Bulk Edit on the user list to set it for many users at once.
If two-step verification is enforced for the whole organization, the per-user setting shows as Enforced and cannot be turned off for individual users.
Checking a user's verification state
The Security tab of a user's profile shows the user's enrolled 2-Step Verification Methods and Trusted devices — devices on which the user chose not to be asked for a code again. See User accounts.
Related pages
- Password policy — where the enforcement setting lives.
- Single sign-on — the SSO exemption.
- Signing in — the sign-in experience with two-step verification.