Two-Factor Authentication

Two-Factor Authentication — A Second Factor on Every Login

Add a time-based one-time password step to SmartSuite login and enforce it across the workspace—protecting accounts from credential theft, satisfying security policy, and keeping enforcement in admin hands.

What Is Two-Factor Authentication?

Two-Factor Authentication is a SmartSuite capability that adds a time-based one-time password (TOTP) step to login, generated by an authenticator app on the Member's device. It helps security-minded organizations protect accounts against stolen or reused passwords—and lets Workspace Administrators require it for everyone or selectively by role. Two-Factor Authentication is available on Professional and Enterprise plans.

TOTP Security

Verify Logins With the Authenticator Apps Teams Already Use

SmartSuite's second factor is app-based TOTP—codes from Google Authenticator, Microsoft Authenticator, Duo Mobile, or Twilio Authy, not interceptable SMS texts. Each Member enrolls from Manage Two-Factor Authentication in their profile and can set a default authenticator method.

Setup is a one-time scan; from then on, every login pairs the password with a code only the Member's device can produce.

Admin Enforcement

Enforce Two-Factor Authentication by Role or Workspace-Wide

From Workspace Administration, Administrators require 2FA for all Members or selectively by role—mandating it for privileged Administrator accounts first, then rolling it out to the whole workspace. Enforcement is policy, not a request: affected Members must enroll to keep signing in.

When a Member loses a device, an Administrator resets their 2FA enrollment so they re-register a new authenticator at next login—recovery without a security exception.

Platform Context
How GRC Teams Use

Two-Factor Authentication

Password-only login is the finding no security review lets slide. Two-Factor Authentication gives GRC teams an enforceable second factor with a clean recovery path.

Security Policy Mandates

An organization's information security policy requires MFA on all business systems. Administrators enforce 2FA workspace-wide from one setting—and the requirement itself becomes reviewable evidence.

Privileged Account Protection

A security team requires 2FA only for Administrator-role accounts first, hardening the credentials that control permissions, billing, and workspace settings before a broader rollout.

Governed 2FA Recovery

A Member loses their phone. An Administrator verifies identity, resets the 2FA enrollment, and the Member re-registers a new authenticator at next login—access restored through a documented process instead of a policy exception.

Phased Enforcement Rollout

Introduce 2FA role by role—Administrators, then Solution Creators, then all Members—using role-based enforcement to sequence enrollment and show steady, evidenced progress toward full coverage.

Layered Login Defense

Combine Two-Factor Authentication with Session Timeout Settings and IP Address Restrictions—verify the person, control the session, and restrict the network in one governance stack.

Works Better Together
Related Features

Password-only login is the finding no security review lets slide. Two-Factor Authentication gives GRC teams an enforceable second factor with a clean recovery path.

Features FAQ’s
Frequently Asked Questions About
Two-Factor Authentication
What is Two-Factor Authentication in SmartSuite?

Two-Factor Authentication adds a time-based one-time password (TOTP) step to SmartSuite login. Members generate codes with an authenticator app on their device, and Workspace Administrators can require 2FA across the organization.

Which authenticator apps does SmartSuite support?

SmartSuite supports TOTP authenticator apps including Google Authenticator, Microsoft Authenticator, Duo Mobile, and Twilio Authy. Members enroll from Manage Two-Factor Authentication in their profile and can choose a default method.

Does SmartSuite offer SMS or email 2FA codes?

No. SmartSuite's second factor is authenticator-app TOTP, which avoids the interception risks of SMS- and email-delivered codes.

Can administrators require 2FA for everyone?

Yes. From Workspace Administration, admins can enforce 2FA for all Members or selectively by role—for example, requiring it for Administrator accounts only, or for the entire workspace.

What happens if a Member loses their phone?

An Administrator resets that Member's 2FA enrollment. At next login, the Member re-registers a new authenticator app and continues under the same enforcement policy.

Which plans include Two-Factor Authentication?

Two-Factor Authentication is available on Professional and Enterprise plans; it is not included on the Team plan.

Close the Password-Only Gap

Turn on Two-Factor Authentication, enforce it by role or workspace-wide, and make every SmartSuite login prove itself twice.