Require two-factor authentication
Passwords get phished; six-digit codes from a phone mostly don’t travel with them. In a few minutes, every sign-in to your organization will require both.
Two-factor here is TOTP — the standard authenticator-app codes. Any authenticator works: 1Password, Google Authenticator, Authy, your password manager’s built-in one.
1. Enroll yourself first
Section titled “1. Enroll yourself first”Before requiring it for everyone, set it up on your own account — you’ll want to have walked the path you’re about to require.
In your Account settings, open the two-factor section and start enrollment. You’ll get a QR code — scan it with your authenticator app (or type the secret in by hand) — and confirm with the first code the app shows. The secret is shown once, at enrollment; there’s no way to read it back later.
You’ll also get recovery codes: one-time codes that stand in for your phone if you lose it. Store them like the secrets they are — a password manager, not a sticky note.
2. Require it for the organization
Section titled “2. Require it for the organization”As the Owner, open Admin → Authentication and set the policy to require two-factor. From that moment, every sign-in to your organization takes a password and a code.
What your teammates experience:
- Already enrolled — nothing changes except the code prompt at sign-in.
- Not yet enrolled — they’re taken through enrollment before they can continue. Nobody’s locked out; they’re walked in.
You can see who’s enrolled at a glance: Admin → Users shows a 2FA column.
The fine print, stated plainly
Section titled “The fine print, stated plainly”- Strictest wins across organizations. If a person belongs to several FortressFlag organizations and any one of them requires 2FA, that person signs in with 2FA everywhere. Your policy can raise a shared teammate’s bar in their other organizations — a real cost, and we’d rather you hear it from us.
- A lost phone means re-enrolling — a recovery code gets them in, and enrolling again mints a fresh secret. There’s no support path that reads an old secret back; that’s a feature.
Where to next
Section titled “Where to next”- Connect Okta — if your company runs on an identity provider, SSO can replace passwords entirely
- Roles and safety — the policy surface is owner-only