Back to setup

Settings

Two-factor authentication

2FA adds a second check to signing in — a rotating code on top of the password. The important thing to understand before you touch the switch: it covers the whole account, not just you.

1

What turning it on actually does

The switch reads Enforce Two-Factor Authentication (2FA) on all users, and it means it literally. This is one setting for the entire business rather than a personal preference — flip it on and everyone who signs in to this account meets a code prompt from then on, whether they log in with a password, an OTP, or Google or Facebook. It also takes effect at once, in the strongest sense: every signed-in session is ended the moment you enable it, including your own, so expect to be asked to sign in again and don't do this in the middle of someone's shift. Turning it back off is a single click on the same switch with no code required — which is worth knowing in both directions, because anyone who can reach this page can also undo it.
2

Choosing how codes arrive

Switching it on opens a short setup that asks how you'd like codes delivered. Authenticator app shows a QR code you scan with any authenticator you already use, and it works offline once it's set up. Email sends a fresh code to your inbox each time you sign in, which needs nothing installed but does mean you can't get in without your mail. Either way the setup begins by emailing you a code to prove it's you — so even the authenticator route starts in your inbox, and the QR only appears after you've entered that first emailed code. Because 2FA belongs to the account rather than to each person, the authenticator is set up once: the code it generates is the one everybody on the account uses, so whoever enables it needs to pass it on to the team.
3

Signing in from then on

Once 2FA is on, signing in gains one extra screen. After the usual details you're asked for a six-digit code, and it submits itself as soon as the sixth digit lands — there's no button to press. Authenticator users read the current code from their app; email users get theirs sent over, with a Resend Verification code link if it's slow. Enter it wrong too many times and the account locks the attempt for a while, and resending is the way back. Keep the setup code somewhere safe when you first scan it. There are no printed backup codes, so the way back from a lost phone is another signed-in person turning 2FA off from this page.