Skip to content

Require two-factor authentication

Passwords get phished; six-digit codes from a phone mostly don’t travel with them. In a few minutes, every sign-in to your organization will require both.

Two-factor here is TOTP — the standard authenticator-app codes. Any authenticator works: 1Password, Google Authenticator, Authy, your password manager’s built-in one.

Before requiring it for everyone, set it up on your own account — you’ll want to have walked the path you’re about to require.

In your Account settings, open the two-factor section and start enrollment. You’ll get a QR code — scan it with your authenticator app (or type the secret in by hand) — and confirm with the first code the app shows. The secret is shown once, at enrollment; there’s no way to read it back later.

You’ll also get recovery codes: one-time codes that stand in for your phone if you lose it. Store them like the secrets they are — a password manager, not a sticky note.

As the Owner, open Admin → Authentication and set the policy to require two-factor. From that moment, every sign-in to your organization takes a password and a code.

What your teammates experience:

  • Already enrolled — nothing changes except the code prompt at sign-in.
  • Not yet enrolled — they’re taken through enrollment before they can continue. Nobody’s locked out; they’re walked in.

You can see who’s enrolled at a glance: Admin → Users shows a 2FA column.

  • Strictest wins across organizations. If a person belongs to several FortressFlag organizations and any one of them requires 2FA, that person signs in with 2FA everywhere. Your policy can raise a shared teammate’s bar in their other organizations — a real cost, and we’d rather you hear it from us.
  • A lost phone means re-enrolling — a recovery code gets them in, and enrolling again mints a fresh secret. There’s no support path that reads an old secret back; that’s a feature.
  • Connect Okta — if your company runs on an identity provider, SSO can replace passwords entirely
  • Roles and safety — the policy surface is owner-only