Settings — Security
The Settings ▸ Security page governs organization-wide sign-in security policy. It is admin-only (Owner / Admin). Your own account security — password, personal 2FA enrolment, active sessions — lives under Account ▸ Security; this page sets the policy for the whole organization.

Require two-factor authentication
Section titled “Require two-factor authentication”When enabled, every team member must set up an authenticator app and is prompted to enrol the next time they sign in. They cannot turn 2FA off for themselves while the policy is on.
You must enable 2FA on your own account first — otherwise enabling the policy would lock you out. The counter shows how many users are already enrolled before you flip it on.
Trusted devices (“Remember this device”)
Section titled “Trusted devices (“Remember this device”)”Controls whether team members may mark a device as trusted to skip two-factor for 30 days after a successful verification.
| Setting | Behavior |
|---|---|
| Allowed (default) | A “Remember this device for 30 days” option appears during 2FA; on a remembered device the member skips the 2FA step until it expires or is revoked. |
| Disabled | The option disappears and every sign-in requires two-factor, even on a previously trusted device — the strictest posture. |
Individual trusted devices can still be reviewed and revoked by each user under Account ▸ Security.
Anatomy of the page
Section titled “Anatomy of the page”The page is organized into tabs:
- Policy — the org-wide 2FA-required and trusted-device toggles described above.
- Active sessions — every member’s currently active sign-in sessions.
- Trusted devices — every member’s remembered devices, reviewable and revocable org-wide.
Permissions and scope
Section titled “Permissions and scope”| Role | View | Manage |
|---|---|---|
| Owner / Admin | ✓ | ✓ |
| Member | ✗ (uses Account ▸ Security for self) | ✗ |
Troubleshooting
Section titled “Troubleshooting”| Symptom | Most likely cause | Fix |
|---|---|---|
| Can’t enable the 2FA policy | You haven’t enrolled 2FA yourself | Set up 2FA under Account ▸ Security, then retry |
| A member still skips 2FA after you tightened policy | They have a live trusted device | Disable trusted devices, or revoke the device here |
| Policy on but a member never enrolled | They haven’t signed in since | They’ll be forced to enrol on next sign-in |
Related pages
Section titled “Related pages”- Account ▸ Security — per-user password, 2FA, and sessions
- Settings ▸ Audit Log — sign-in and policy-change events