Skip to main content

Require MFA for your organization

Who: organization owners and administrators. Where: Administration → OverviewMulti-factor authentication.

This workflow covers the MFA opt-in implementation reviewed on August 31, 2026. It requires the corresponding Core, Web, control-plane, migration, and IAM changes. A missing control in an older deployment is not a reason to bypass MFA checks.

Default behavior

  • Newly onboarded organizations in this release start with MFA off.
  • Existing organizations retain their MFA requirement during the migration.
  • After an administrator enables MFA, every human member must use an authenticator app. There is no disable control in this UI.
  • MFA verified describes the current session. Off or Required for all members describes the organization policy; these are different facts.

Before you enable MFA

Notify members, make sure they can access an authenticator app, and agree on an administrator-assisted recovery process. Include owners and administrators in that preparation. Do not assume recovery codes or a self-service reset exist.

Review the current policy

Open Administration → Overview and locate Multi-factor authentication. If it already says Required for all members, the organization has opted in.

Enable and confirm

Select Enable MFA. Read the warning that the requirement applies to everyone and cannot be turned off here. Confirm with Enable MFA and sign in.

Complete your own MFA setup

You are redirected to login. Sign in, enroll an authenticator if needed, then sign in again to verify the factor. Already-enrolled users complete their existing challenge.

Have members complete setup

Share the sign-in guide. Password-only sessions lose access on subsequent protected requests until the member completes an MFA sign-in. Already-running work is not retroactively cancelled by this setting.

If enabling fails

Refresh the displayed policy and record the sanitized error and time. Ask the operator to check the tenant configuration and Core's tenant-update permission. The backend enables the tenant's TOTP capability before persisting the organization's requirement so a provider failure does not leave members required to enroll an unavailable factor.

If the operation's outcome is uncertain, verify the current policy before retrying. Never ask members to share their QR code or authenticator secret as a troubleshooting step.