Two-step verification
Two-step verification is a more secure way to protect your accounts. It combines a password (something you know) with a second factor (something you own), making it harder for attackers to gain access.
The 2 most common verification methods are:
- Text message: A PIN code sent to your mobile phone.
- Authenticator app: A time-based code generated on your device
Set up two-step verification
To enable two-step verification, go to My account > User profile > Basic settings > Security.
Once enabled, you're asked to verify your identity with the chosen method every time you log in. You're also asked for a new code after 30 days or whenever your IP address changes.
Text message
- Enable the Text message option.
- Enter your phone number and click Get code.
- Enter the 6-digit code you got, then click Confirm.
Authenticator app
- Enable the Authenticator app option.
- Install an authenticator app on your mobile device. We recommend Google Authenticator (iOS or Android), but any authenticator app works.
- Open the app and scan the QR code to get a 6-digit code.
- Enter the code, then click Confirm.
Backup codes
Backup codes let you log in if you don't have access to your mobile device. When you enable this option, you get 10 single-use codes. Store them somewhere secure.

Example backup codes
NoteBackup codes aren't part of two-step verification itself. They're a recovery option only. Use them if you lose access to your device.
Enforce two-step verification
You can make two-step verification mandatory for all users in your organization. Go to Administration > Settings > Security > Two-step verification.

There are 2 options:
- Optional: Users can choose whether to use two-step verification (default).
- Mandatory for all users: Every user in the organization and its projects must use two-step verification.
Only a Cloud Organization Admin can change this setting.
Force existing users to enroll
Setting two-step verification to mandatory doesn't automatically force existing users to re-authenticate or complete enrollment. Users who were already logged in when you made the change may remain active without enrolling.
To force enrollment, a Cloud Organization Admin can terminate individual user sessions. Once a session is terminated, the user has to log in again and set up two-step verification before they can continue. Note that:
- You can only terminate sessions for users in the same identity domain.
- There's no bulk action. Sessions must be terminated one user at a time.
If terminating sessions manually isn't practical, you can wait for sessions to expire naturally instead. The default session length is 24 hours, but sessions extend as long as the user stays active. If a user opens the browser tab every day, their session can last over a month. To gauge timing, check each user's last login time before deciding whether to wait or terminate manually.
NoteEach user account can have only one active session at a time. Signing in on a new device or browser ends the previous session automatically.
Login attempt without 2FA set up
If two-step verification becomes mandatory while a user doesn't have it set up yet, they aren't blocked immediately. Enforcement only applies the next time they log in. If they're already logged in when you enable it, they can keep working without setting up 2FA until their session ends (see Force existing users to enroll).
The next time this user logs out and logs back in, they land on the two-step verification setup page instead of the product. There's no way to skip or defer this step. They have to complete setup before they can continue.
Users don't get advance notice (email or in-app banner) before enforcement takes effect. The setup page at their next login is the first sign they see.
Reset two-step verification
If you change your phone number or lose your device, you need to reset two-factor authentication (2FA) to regain access. To request a reset:
- Submit a 2FA reset request to Support, either yourself or through a colleague.
- Support verifies the request and sends a confirmation email to the address associated with the account.
- Reply to the email to confirm the request is valid.
- Once support receives your confirmation, they reset 2FA for the account.
- After the reset, set up a new 2FA method and log in.
Troubleshooting
Google Authenticator codes not working
If your codes have stopped working or are showing an error, the most likely cause is a time sync issue.
- Open the Google Authenticator app.
- Go to the Menu > Settings > Time Correction for Codes.
- Click Sync Now.
This will automatically correct the time.
Sync time on your device
Go to your device's Settings > Date & Time and turn on automatic time and time zone.
Lost or damaged device
If you've lost your device or it's not working, use your backup codes to log in. This is why it's important to generate and store backup codes securely when you first set up two-step verification.
Updated 11 days ago

