Skip to main content

How do I enable two-factor authentication?

Describes options for enabling and requiring two factor authentication for user logins.

Two-factor authentication adds an extra layer of security to a user's account by asking for a 6-digit code in addition to their password. The code changes every 30 seconds and comes from an authenticator app on the user's phone, such as Google Authenticator (available on Android).

Because signing in then requires the user's phone as well as their password, two-factor authentication makes it much harder for someone else to reach your data.


Enabling it on your own account

Open your user menu in the upper-right corner (your name and profile photo) and choose Username/password. You can also reach this from your own profile by opening the Actions menu and choosing Change username/password.

In the Change username/password window, find the Two Factor Authentication section and click Enable 2FA.

Follow the on-screen instructions: install an authenticator app on your phone, scan the code it displays, and enter the 6-digit code to finish. From then on, you'll enter a fresh code each time you log in.

Tip: You can turn two-factor authentication off at any time by returning to the same Two Factor Authentication section and disabling it.


Requiring it for another user

You will need the Limited Permission and Full Write People permissions to perform this action.

You can require two-factor authentication for another user so they must set it up before they can log in again.

  1. Go to the person's profile and open the Actions menu, then choose Change username/password.

  2. In the Two Factor Authentication section, turn on the Required? toggle.

  3. Click Save.

The next time that user logs in, they'll be prompted to set up two-factor authentication from the login screen before they can access the system.


Setting the policy for your whole organization

You will need the Limited Account permission to perform this action.

You can set a single policy that controls who is required to use two-factor authentication. Open Settings & Tools (cog icon in the tool-bar) and go to Settings & Tools > Your Organization > Security. On the Security page, open the Options tab and find Two Factor Authentication Policy under General.

Choose one of the following policies:

  • As needed - no one is required to use two-factor authentication by default. You can still require it on a per-user basis (see above).

  • All non-guest users - requires two-factor authentication for every user who does not have the Guest role. Use this to require it for staff and volunteers but not regular congregation members.

  • Everyone - requires two-factor authentication for every user, including regular members of your congregation.

Warning: Because turning off two-factor authentication for an account that isn't yours is highly sensitive, only a Super User can do it. Ideally the account holder disables it themselves; a Super User can do it on their behalf if they've lost access to their authenticator app.

Other Helpful Articles

Did this answer your question?