Skip to content

Settings — Security

The Settings ▸ Security page governs organization-wide sign-in security policy. It is admin-only (Owner / Admin). Your own account security — password, personal 2FA enrolment, active sessions — lives under Account ▸ Security; this page sets the policy for the whole organization.

Settings Security — Acme Financial Group demo tenant

When enabled, every team member must set up an authenticator app and is prompted to enrol the next time they sign in. They cannot turn 2FA off for themselves while the policy is on.

You must enable 2FA on your own account first — otherwise enabling the policy would lock you out. The counter shows how many users are already enrolled before you flip it on.

Trusted devices (“Remember this device”)

Section titled “Trusted devices (“Remember this device”)”

Controls whether team members may mark a device as trusted to skip two-factor for 30 days after a successful verification.

SettingBehavior
Allowed (default)A “Remember this device for 30 days” option appears during 2FA; on a remembered device the member skips the 2FA step until it expires or is revoked.
DisabledThe option disappears and every sign-in requires two-factor, even on a previously trusted device — the strictest posture.

Individual trusted devices can still be reviewed and revoked by each user under Account ▸ Security.

The page is organized into tabs:

  • Policy — the org-wide 2FA-required and trusted-device toggles described above.
  • Active sessions — every member’s currently active sign-in sessions.
  • Trusted devices — every member’s remembered devices, reviewable and revocable org-wide.
RoleViewManage
Owner / Admin
Member✗ (uses Account ▸ Security for self)
SymptomMost likely causeFix
Can’t enable the 2FA policyYou haven’t enrolled 2FA yourselfSet up 2FA under Account ▸ Security, then retry
A member still skips 2FA after you tightened policyThey have a live trusted deviceDisable trusted devices, or revoke the device here
Policy on but a member never enrolledThey haven’t signed in sinceThey’ll be forced to enrol on next sign-in