Two-Factor Authentication
Last updated
Last updated
This document defines the Two-Factor Authentication (2FA) verification flow for Members in a Business Organization.
2FA verification occurs after successful email and password authentication, when required by organization security policies.
Members cannot configure, enable, or disable 2FA methods.
If you are a Member, 2FA verification may appear during sign-in.
You only need to:
Follow the on-screen verification instructions
Use the 2FA method required by your organization
No prior configuration is needed unless instructed by your administrator.
This guide helps Members understand:
When 2FA verification is required
What 2FA verification methods may be used
How to complete 2FA verification successfully
Before completing 2FA verification:
2FA verification is required when:
The verification method is automatically selected based on organization policy.
Step 1: Select Authenticator as the verification method.
Step 2: Open your authenticator app on your mobile phone or tablet.
Step 3: Enter the verification code displayed in the app.
Once the code is validated, verification is completed automatically.
Step 1: Select Email as the verification method.
Step 2: Check your email inbox for the verification message.
Step 3: Enter the verification code provided.
Verification completes automatically once the code is validated.
Step 1: Passkey is selected as the default verification method.
Step 2: Click Continue.
Step 3: Verify your identity using a registered passkey.
Follow the on-screen instructions provided by your device to complete verification.
After successful 2FA verification:
If 2FA verification fails:
You have already signed in with email and password
2FA is enabled or enforced by your organization
You have access to the required verification method
Mandatory 2FA is enforced by the organization
Risk-based access control detects unusual behavior
You sign in from a new device, location, or network
Note: If you do not receive the verification code, see What should I do if I don't receive a verification code when signing up or forgot password?
Sign-in is completed
You are redirected to your dashboard or assigned workspace
Your session continues normally
You may retry within allowed limits
Excessive failures may temporarily block sign-in
You may be prompted to use an alternative method if allowed by policy
Verification codes are time-limited and single-use
Verification attempts are logged for audit purposes
Rate limiting is applied to prevent abuse
2FA may be required again for high-risk actions
Members cannot change 2FA settings
2FA methods are enforced by the organization
Password reset does not disable 2FA enforcement
Loss of access to 2FA method requires administrator assistance
Item
Member
MFA Configuration
❌ Not allowed
MFA Verification
✅ Required (if enforced)
Supported Methods
Authenticator, Email, Passkey
Retry Attempts
✅ Limited
MFA Bypass
❌ Not supported