How to require MFA for your coworkers and partners?

Learn how to make multi-factor authentication mandatory for the people who access your workspace, and what your coworkers and partners will see the next time they sign in.

By default, MFA is optional: each person decides whether to secure their own account with an authenticator app. As an admin, you can make it mandatory instead, for your coworkers, for your partner users, or for both.

Prerequisites

  • You need an Admin or Owner role to change these settings.

Require MFA

From the top-right menu, open Account Settings, then click Security. The Multi-factor authentication section is at the top of the page.

Turn on the group you want to cover:

  • My coworkers: Require MFA for my coworkers, meaning everyone on your own team who signs in to this workspace.
  • Partner users: Require MFA for partner users, meaning the people from your partner companies who sign in to your partner portal.

The two toggles are independent, so you can require MFA for your team without changing anything for your partners.

Click Save. Because turning a requirement on affects everyone in that group, Kiflo asks you to confirm with the Enforce multi-factor authentication dialog before saving.

What the affected users see

There is no grace period, and nobody is signed out when you save. The requirement applies the next time each person reaches the workspace:

  • People who already use an authenticator app notice nothing new. They keep entering their 6-digit code at sign-in, as before.
  • People without MFA are stopped by a Set up multi-factor authentication screen that cannot be dismissed. Your coworkers are told that your organization requires MFA to continue, and partner users are told that your company requires it to keep accessing their partner portal. They scan the QR code, enter a code from their authenticator app, and get access straight away.

Users who are already signed in are not interrupted immediately. They are asked to set MFA up within a few minutes, the next time their session is renewed.

MFA and single sign-on cannot both be enforced

With SSO, authentication is delegated to your identity provider, so Kiflo never asks those users for a code of its own. Any MFA you need there is configured in your identity provider.

Because of this, the two settings are mutually exclusive per group:

  • If SSO is already enforced for a group, its MFA toggle is replaced by a note explaining that MFA cannot be required for those users.
  • The reverse also applies. Once MFA is required for a group, the Enforce option of the matching SSO dropdown explains that single sign-on cannot be enforced for them.

Setting SSO to Enable rather than Enforce does not conflict with MFA. Those users can still sign in with a password, and when they do, they are asked for their MFA code.

Your users cannot turn MFA off afterwards

MFA in Kiflo belongs to the person, not to the workspace: one authenticator app covers every workspace they can access. So while any of their workspaces requires MFA, the Disable button on their User Preferences → Security page stays greyed out, with the tooltip One or more of your workspaces requires MFA. It becomes available again if you turn the requirement off.

Did this answer your question? Thanks for the feedback There was a problem submitting your feedback. Please try again later.