Require two-factor authentication
Owners can require two-factor authentication (2FA) for everyone in the workspace, or just for certain roles — owners, admins, or members. Once turned on, the requirement applies right away: covered users are asked to set up an authenticator app the next time they make a request.
Who can do this
Only workspace owners can view and change this setting. It doesn’t appear for admins or members, even if they otherwise have broad permissions — this is a deliberate exception so that enforcing 2FA can’t be relaxed by anyone other than an owner.
Turning it on
- Go to Settings → Security → Require two-factor authentication.
- Switch on Require two-factor authentication. It’s off by default.
- Choose who it applies to:
All users — every member of the workspace must enrol in 2FA.
Specific roles — pick which roles are covered (Owners, Admins, Members). Toggle each role on or off individually.
There’s no separate “Save” step — each toggle you flip is applied straight away.
What happens for covered users
As soon as a user falls under the policy — either because “All users” is selected or because their role is toggled on — they’re asked to set up an authenticator app the next time they make a request to the workspace. There’s no delay for a cache to catch up; the change is live immediately.
Users who aren’t covered (for example, members when the policy is scoped to owners and admins only) aren’t affected and won’t see an enrolment prompt.
Scoping to specific roles
When you switch to Specific roles, the roles list starts with Owners and Admins already selected — the two most privileged roles — rather than nobody, since an empty selection would mean the requirement doesn’t apply to anyone.
You can then turn individual roles on or off:
- Turning a role on means anyone with that role must have 2FA enrolled.
- Turning a role off removes that role from the requirement.
If you turn off the last remaining role, the two-factor requirement is switched off entirely rather than silently expanding to cover everyone. If you want it to cover everyone, choose All users instead of leaving the role list empty.
Turning it off
Switch Require two-factor authentication back off. This removes the requirement for every role immediately — no one is prompted to enrol going forward, though anyone who already set up 2FA keeps it enabled on their own account unless they remove it themselves.
Audit trail
Every change to this policy — turning it on or off, and any change to which roles are covered — is recorded as a security event, along with the owner who made the change. Use this to confirm when 2FA enforcement was enabled, narrowed, widened, or removed, and by whom.
Things to know
- This is a tenant-level policy — it’s set per workspace, not per user.
- Only owners can view or change it; it won’t show up in the Settings navigation for other roles.
- The change is immediate. There’s no rollout delay or grace period built into the setting itself — plan communication to your team before turning it on if you want to give people advance notice to install an authenticator app.