Skip to main content

Set Up Two-Factor Authentication

Two-factor authentication (2FA, also called multi-factor authentication or MFA) adds a second check at sign-in beyond a password — usually a time-based code from an authenticator app. This page shows an admin how to turn it on and roll it out to Authors.

If your account signs in through SSO with Microsoft Entra ID or another identity provider, enforce 2FA in that provider instead. In that setup the platform trusts the identity provider's checks, so the steps below apply mainly to accounts that sign in with a platform username and password.

Before you begin

  • Admin access to the account's security or sign-in settings.
  • An authenticator app on each user's phone (any standard TOTP app works).
  • A short heads-up to Authors before you enforce 2FA, so no one is locked out mid-task.
  • Decide the scope: your own account only, or required for everyone.

Steps

  1. Open the account's sign-in security settings (confirm the exact steps in your account).
  2. Locate the two-factor / multi-factor authentication option and enable it.
  3. When prompted, scan the displayed QR code with your authenticator app and enter the generated code to confirm the pairing.
  4. Save any backup or recovery codes somewhere secure — these let you sign in if you lose the device.
  5. To require it for the whole account, switch the setting from optional to enforced for all users.
  6. Notify Authors so they enroll their own devices at next sign-in.

Result

At the next sign-in, users enter their password and are then prompted for a one-time code from their authenticator app. Confirm by signing out and back in — you should see the second-step prompt.


Canonical terms: Author, Edition, Folder (Project Folder), Broadcast. See the Glossary.