Skip to main content
Organization owners can require every member to use two-factor authentication. It’s usually the answer when security review asks how you control access to a system that reaches production.

Turning it on

From your organization’s settings, switch on Require two-factor authentication. Owner only. Nobody is locked out immediately. Members who don’t yet have two-factor set up get a seven-day grace period, counted from the moment you turn the requirement on, and are prompted to set it up each time they sign in.

What happens after the grace period

A member who still hasn’t set up two-factor is blocked from the product until they do. They see a page explaining why, with two ways forward:
  • Set up two-factor — the normal flow, and they’re back in immediately afterwards
  • Leave the organization — for someone who was added by mistake, or no longer needs access
Their account and personal projects are untouched. The block applies to the organization that requires it.
Turn the requirement on at the start of a week and tell your team the same day. The grace period is generous, but the first most people hear about it is the sign-in prompt.

Checking who’s covered

The members list shows each person’s two-factor status, so you can see who still needs to act before the deadline rather than finding out when they’re blocked.

Turning it off

Switch the requirement off and the block lifts immediately. Members who already set up two-factor keep it — disabling the policy doesn’t disable anyone’s security.

Set up two-factor

What your members will go through.