Enforce Account-Wide Multi-Factor Authentication

Table of Contents


Multi-factor authentication (MFA) adds an extra verification step when members sign in. Enforce MFA on an account to require every member to use it. For why MFA matters, see Account Security.

When multiple users manage an account, enforcing MFA reduces the risk of compromised credentials. This feature is available on Teams plans and higher for accounts that manage members.

Enabling MFA enforcement

You can enable MFA enforcement from account settings.

You can only enable MFA enforcement when all members already have MFA enabled. If a member does not enable MFA, remove them from the account to turn on enforcement, then re-invite them. They will be asked to enable MFA before they can join.

To enable MFA enforcement
  1. Select the relevant account from the account switcher, then open .

    screenshot: account settings

  2. Select the tab on the left.
  3. Scroll to the card. When all members have MFA enabled, you can turn on enforcement.

    screenshot: mfa settings for account

  4. If members do not have MFA enabled, you will see a list of non-compliant users. You can remove those members from the card.

    screenshot: non compliant mfa users

,

Disabling MFA enforcement

To disable MFA enforcement
  1. Select the relevant account from the account switcher, then open .

    screenshot: account settings

  2. Select the tab on the left.
  3. Scroll to the card, then click .

    screenshot: disable mfa

Disabling MFA while on an enforced team

You can always disable multi-factor authentication on your user profile. Doing so automatically removes you from every account that enforces MFA.

Warning

If you disable MFA, you are immediately removed from all accounts that enforce MFA. Only disable MFA on your user if you no longer need access to those accounts.

Inviting new members to an MFA-enforced account

You can invite new people to your account without restrictions. When you invite users who do not yet have DNSimple users, they are asked to enable MFA after signup before they can join.

If the user already has a DNSimple user, they can join only when they have MFA enabled.

Have more questions?

If you have questions about enabling or disabling MFA enforcement, contact support, and we will be happy to help.