---
title: Two-factor authentication enforcement
slug: two-factor-authentication-enforcement
description: Enforce two-factor authentication (2FA) for your organization (Enterprise plans only). 
image: https://archbee-image-uploads.s3.amazonaws.com/oAyFj2GHlBeBVWF5OAir2/e_qHb1m7hHbasnTc0QETS_1.png
docTags: 
createdAt: 2026-02-09T10:02:11.838Z
---

:::hint{type="info"}
This feature is available to **Enterprise** customers.
:::

Organization Admins and Owners can enforce **Two-factor authentication (2FA)** within their organization, requiring all users to enable it.&#x20;

## Key benefits

- **One-step enforcement**: Make 2FA mandatory for all users in one action
- **Reduced security risks**: Prevent unauthorized access and potential account takeovers
- **Locked in protection:&#x20;**&#x45;nsure users can't accidentally or intentionally turn off 2FA, so your security stays locked in place

## Limitations

2FA enforcement applies only to users who sign in using Make’s native authentication method (email and password).

If a user signs in through an external provider (e.g., Google) or an Identity Provider (SSO/SAML), this Make-level enforcement does not apply. In these cases, 2FA must be configured and enforced within the external provider or Identity Provider.&#x20;

## Enable 2FA enforcement in the Organization

:::hint{type="warning"}
As soon as you enforce 2FA in your Organization, users who haven't set up 2FA before and sign in using Make's native authentication method (email and password) will be signed out immediately. 

We recommend planning 2FA enforcement ahead of time to avoid disruption:

- Schedule for off-hours, evenings, or weekends when your team isn't actively working.
- Inform your team 24-48 hours in advance; explain what's happening, and that the setup takes about 5 minutes.
- Let users save their work: make sure there's time before you enable it.&#x20;
:::

To enable 2FA enforcement in your Organization:

::::WorkflowBlock
:::WorkflowBlockItem
In the left sidebar, click **Org**.
:::

:::WorkflowBlockItem
Click the profile icon and go to **Organization** **settings**.
:::

:::WorkflowBlockItem
Click **Enforce 2FA**.

::Image[]{src="https://api.archbee.com/api/optimize/oAyFj2GHlBeBVWF5OAir2/HZRZpR3gILvftFmU7LEOy_enfoce-2fa.png" size="50" isUploading="false" position="center" width="554" height="541" darkWidth="554" darkHeight="541" showCaption="false"}
:::

:::WorkflowBlockItem
In the next window, review the warning that all users in your organization will be signed out immediately and required to use 2FA to sign in.

Check the confirmation box and click **Enable 2FA**.

::Image[]{src="https://api.archbee.com/api/optimize/oAyFj2GHlBeBVWF5OAir2/0BezXgEE1eBGUK4ThdZbM-20260211-125943.png" size="50" width="788" height="736" position="center" darkWidth="788" darkHeight="736" showCaption="false"}
:::
::::

You will see a message confirming that 2FA changes have been saved.&#x20;

## Set up 2FA

Once 2FA enforcement is enabled, users who haven't configured 2FA before and sign in using Make's native authentication method (email and password) will be signed out immediately. Upon signing in, they will see a warning that their account now requires 2FA.

To set up 2FA, users have to:

:::::WorkflowBlock
:::WorkflowBlockItem
Sign in using their Make email and password.
:::

:::WorkflowBlockItem
Scan the QR code using an authenticator app (e.g., Google Authenticator, Authy, Microsoft Authenticator, or 1Password).

If scanning is not possible, click **Can't** **scan?** and manually enter the provided key to the authenticator app.

::Image[]{src="https://api.archbee.com/api/optimize/oAyFj2GHlBeBVWF5OAir2/uJw-RpKRbmA_xrjyO-Igq-20260210-093522.png" size="50" width="1648" height="2144" position="center" darkWidth="1648" darkHeight="2144" showCaption="false"}
:::

:::WorkflowBlockItem
Enter the **One-time code** generated by the authenticator app along with Make **Password**, and click **Continue**.

::Image[]{src="https://api.archbee.com/api/optimize/oAyFj2GHlBeBVWF5OAir2/jndeQZITGEcXuTxmxuxNK-20260210-093947.png" size="50" width="1648" height="1052" position="center" darkWidth="1648" darkHeight="1052" showCaption="false"}
:::

::::WorkflowBlockItem
Save your recovery codes. 

:::hint{type="warning"}
Save the provided one-time recovery passwords in a safe place. They can be used to regain access to the account with 2FA if a mobile device is lost or stolen, or the authenticator app is removed from the phone.&#x20;
:::

Click **Copy to clipoboard** to copy the one-time passwords, or click **Download** to save them in a TXT file.

::Image[]{src="https://api.archbee.com/api/optimize/oAyFj2GHlBeBVWF5OAir2/vWxw6vUOflOHn23UsUudv-20260210-094946.png" size="40" width="1780" height="2348" position="center" darkWidth="1780" darkHeight="2348" showCaption="false"}
::::

:::WorkflowBlockItem
After saving, click **Continue**.
:::
:::::

Users who belong to only one organization will be redirected to their Make Org page. Users who belong to multiple organizations will need to select the organization before being redirected to their Make Org page.&#x20;

## Check 2FA status

After enabling 2FA enforcement, organization Admins and Owners can see at both the organization and team levels who completed setup and who didn't.&#x20;

### Check 2FA status at the organization level

To check the user's 2FA status at the organization level:&#x20;

::::WorkflowBlock
:::WorkflowBlockItem
In the left sidebar, click **Org**.
:::

:::WorkflowBlockItem
Switch to the **Org** **Users** tab.
:::

:::WorkflowBlockItem
Click the icon in the upper-right corner of the table and check the box for 2FA status.

![](https://api.archbee.com/api/optimize/oAyFj2GHlBeBVWF5OAir2/S7OgF_O11IbULSGzjypb4-20260212-113148.png)
:::
::::

You will see a new **2FA Status** column with each organization member's 2FA status.

### Check 2FA status at the team level

To check the user's 2FA status at the team level:&#x20;

::::WorkflowBlock
:::WorkflowBlockItem
In the left sidebar, click **Team**.
:::

:::WorkflowBlockItem
Switch to the **Team** **Users** tab.
:::

:::WorkflowBlockItem
Click the icon in the upper-right corner of the table and check the box for 2FA status.

![](https://api.archbee.com/api/optimize/oAyFj2GHlBeBVWF5OAir2/H9fHIJ5hV-ClyXbQSHfaZ-20260212-092215.png)
:::
::::

You will see a new **2FA Status** column with each team member's 2FA status.

![](https://api.archbee.com/api/optimize/oAyFj2GHlBeBVWF5OAir2/NiGiGDqL6kchxDzY70KZj-20260212-092847.png)

## Disable 2FA enforcement in the Organization

When 2FA enforcement is on, users can't turn off 2FA themselves. Only Organization Admins or Owners can disable it. 

To disable 2FA enforcement in your Organization:

::::WorkflowBlock
:::WorkflowBlockItem
In the left sidebar, click **Org**.
:::

:::WorkflowBlockItem
Click the profile icon and go to **Organization** **settings**.
:::

:::WorkflowBlockItem
Click **Turn off 2FA enforcement**.
:::

:::WorkflowBlockItem
In the next window, review the warning that once 2FA enforcement is turned off, users will no longer be required to sign in with a verification code.&#x20;

Check the confirmation box and click **Turn off enforcement**.

::Image[]{src="https://api.archbee.com/api/optimize/oAyFj2GHlBeBVWF5OAir2/_pNuxSuB4P6i7tfs7jtDk-20260209-171406.png" size="50" width="2052" height="1292" position="center" darkWidth="2052" darkHeight="1292" showCaption="false"}
:::
::::

You will see a message confirming that 2FA changes have been saved.
