Multi-factor authentication
Multi-factor authentication
Multi-factor authentication
MFA adds a second factor (a TOTP code from an authenticator app) to dashboard logins. By default it’s optional per member. Most teams turn it on org-wide once they have a few people using the dashboard.
If your team uses SSO, MFA is usually enforced at the IdP rather than at Agent Handler - your IdP already requires the second factor before SSO completes, so layering MFA at Agent Handler too is redundant.
Each member sets up their own. From Settings → Profile:
From the next login on, MFA is required for your account.
Admins can require MFA for everyone in the org at Settings → Organization → Security. Once on:
Turn this on once your team is small enough that a few minutes of friction per person is acceptable, or when your security review asks.
If a member loses their authenticator and their recovery codes, an admin can reset their MFA. From Settings → Members, click the member, then Reset MFA. The member can re-enroll on their next login.
Reset is logged in the Audit Trail - a record exists of who reset whose MFA and when.
See plans, usage, and how to upgrade in Billing and usage.