For what MFA adds to either sign-in method, see the Overview.
Enforce MFA for all users
- In ION, go to Settings > Organization > Authentication.
- In the Multi-Factor Authentication card, turn on Require MFA for all users.
Org-wide MFA applies to everyone the moment you turn it on. To avoid locking
users out, confirm your team can enroll an authenticator app, and validate the
change in a sandbox tenant first if you have one.
Enforce MFA for yourself
You can enable MFA on your own profile without org-wide enforcement enabled. After enabling, log out and sign back in to start the MFA setup flow. If you lose access to your MFA device, see Troubleshooting sign-in issues.