Skip to main content
With MFA required, users set up multi-factor authentication and use it each time they sign in. A user who hasn’t set it up yet is prompted at their next sign-in. For how sign-in works, see the authentication overview.

Enforce MFA for all users

  1. In ION, go to Settings > Organization > Authentication.
  2. In the Multi-Factor Authentication card, turn on Require MFA for all users.
Org-wide MFA applies to everyone the moment you turn it on. To avoid locking users out, confirm your team can enroll an authenticator app, and validate the change in a sandbox tenant first if you have one.

Enforce MFA for yourself

You can enable MFA on your own profile without org-wide enforcement enabled. After enabling, log out and sign back in to start the MFA setup flow. If you lose access to your MFA device, see Troubleshooting sign-in issues.