Overview
Use Multi-Factor Authentication (MFA) in Enterprise Hub to strengthen security and mitigate breach risks. You can configure MFA on a role basis with either Time-based One-Time Password (TOTP) or SMS verification to protect accounts.
Who uses this feature
Office employees
Applies to all business types
Feature configuration
Account configuration is required to use this feature. Please contact Technical Support for details.
Things to know
Ensure that all users who need to administer MFA configurations have the necessary user permissions enabled in the system. For more, see step 4 in the Grant access to User Management section.

Organizations can enable one or both authentication methods, SMS or TOTP, for their employees.
When you enable MFA for a user, they'll be immediately logged out and prompted to set up your organization's selected authentication methods upon logging back in.
Note: Make sure to inform them of this change beforehand.
If a user encounters issues during the verification process, the user should contact their administrator for assistance. You have the ability to disable and reset MFA. For more, see Manage MFA configurations.
Glossary
Multi-Factor Authentication (MFA): A security method that requires you to verify your identity using two or more authentication factors, for example, password or code.
Short Message Service (SMS): A text messaging service used to send verification codes or notifications to mobile devices.
Time-based One-Time Password (TOTP): A temporary, time-sensitive code generated by an authenticator app for secure login verification.
Multi-Factor Authentication (MFA) Enforcement: An Enterprise Hub security policy that auto-enables Multi-Factor Authentication (MFA) for all Enterprise Hub users to strengthen account protection, prevent unauthorized access, and align with security best practices with minimal disruption.
General requirements for Enterprise Hub administrators
The system automatically configures MFA—either SMS or TOTP. For more, see Multi-Factor Authentication (MFA) Enforcement for Administrators.
Ensure that all users who need to administer MFA configurations have the Manage MFA permission enabled in the system. For more, see Grant access to User Management.
When the system automatically configures MFA for a user, they'll be immediately logged out and prompted to set up your organization's selected authentication methods upon logging back in.
Note: Make sure to inform them of this change beforehand.
If a user encounters issues during the verification process, they should contact their administrator for assistance. You have the ability to disable and reset MFA. For more, see Manage MFA configurations in Enterprise Hub.
SMS: Mobile Phone Verification
This method requires a valid mobile number to receive a one-time passcode by text message.
Ensure to add mobile phone numbers to all users who use SMS MFA.
Double-check that all mobile phone numbers on file are correct and accessible by the user, as this is the channel for identity verification during sign-in.
TOTP (Authenticator App)
This method uses an app on a tablet or mobile device to generate rolling codes, offering a highly secure verification factor.
Users can configure TOTP MFA using virtually any authenticator app on their mobile device, for example, Google Authenticator, Microsoft Authenticator, Okta, or LastPass. For more, see Set up MFA with Google or Microsoft Authenticator.
Users may use an existing authenticator app or download a new one from their device's app store, such as, App Store or Google Play Store.
This app works even if the device isn't connected to the internet or mobile data isn't available.
Setup MFA for users
There are 2 methods to set SMS or TOTP for your users:
Method 1: Individual enablement
Method 2: Bulk enablement
Set MFA for an individual user account
In Enterprise Hub, click User Management.
In the Users section, click +Add User.
Fill out user details as described in the Create users section.
Go to the Multi-Factor Authentication (MFA) section and select one or both of options:
Mobile SMS: If you prefer to use SMS-based (text) verification.
Note: The user must have a mobile phone number saved to their profile.
Authentication App: If a user doesn't have a phone number or prefers an authenticator app.

When finished, click Save.
Note: When you enable both MFA methods, users can select and set up their preferred method during login.
Enable or update MFA in bulk in Enterprise Hub
To update multiple users at once:
In User Management, click Security.
Select the checkbox for all users you want to enable MFA.

Click the action and select the MFA option you want to enable for the user.

The system enables MFA on the selected user account.
Note: After MFA is enabled, the system immediately logs the user out and prompts them to set up MFA on their next login.
Manage MFA configurations in Enterprise Hub
In User Management, click Security.
On the Security screen that opens, you can:
Search for users.
Filter by MFA Type, Phone number status, or Account status.
Enable MFA.
View user MFA details
On the Security screen, click More
.Select View Details.

On the drawer that opens, view or edit details.
When finished, click Done.

Edit user profile
On the MFA screen, click More
.Select Edit. You are redirected to the user profile.

View MFA error logs
On the Security screen, click More
.Select the View MFA error logs option.

On the Multi-Factor Authentication Errors window that opens, you can:
Verification Init Failed
SMS Service Unresponsive
Verification SMS Undelivered
Verification SMS Delivery Unknown
Verification SMS Send Failed
User Reached Verification Initialization Limit
User Reached Code Sending Limit
Not My Number
User Code Verification Failed
TOTP Verification Failed
TOTP Secret Reset
TOTP Account Locked
TOTP Max Attempts Reached

Lock users
On the Security screen, click More
.Select the Lock user account option.

In the confirmation window that opens, click Lock Account to proceed with locking the employee or technician account, or click Cancel to dismiss the action.

Reset TOTP authenticator
On the Security screen, select a user.
Click Actions.
Select Reset Authenticator.

On the window that opens, click Reset.

Disable TOTP authenticator
On the Security screen, select a user.
Click Actions.
Select Disable Authenticator.

On the window that opens, click Disable.