Skip to content

Requiring two-factor authentication across your team

What the account-wide two-factor requirement does, how members enrol and recover access, how API keys and probes behave, and what gets audited.

By the UptimeMonitor360 team · updated

Enrolment for one person

Any member can enable two-factor authentication from their account page: confirm the password, add the secret to an authenticator app (any TOTP app; the otpauth URI is shown), enter the current code, and store the ten one-time recovery codes that appear exactly once. From then on, sign-in asks for a code after the password; the "trust this device" option skips the prompt on that browser for 30 days.

Recovery

A recovery code signs you in once and is then spent. Use the account page to disable and re-enable two-factor if you lose the authenticator, which also issues fresh recovery codes. Owners cannot read anyone's secret or codes; an owner who needs to let a locked-out member back in removes and re-invites them.

The account-wide requirement

Account owners can require two-factor for every human member from Team and clients → Security policy. The switch is refused until the owner has two-factor enabled themselves, so the policy can never lock out the person who sets it. Once on, every member without two-factor is redirected from any workspace page to their account page with an explanation, enrols, and continues to the workspace. Client viewers are members too and are covered.

What is not affected

API keys and probe tokens are machine credentials and keep working. Issuing, rotating and revoking keys is done by a signed-in member in the workspace, so those actions require a member who satisfies the policy. The security page in the documentation lists these rules precisely.

Audit trail

Switching the requirement on or off is recorded in the audit log with the acting user and the number of members that lacked two-factor at that moment. Sign-ins, recovery-code use and session revocations are visible on each member's account page.

Monitor the behaviour described here continuously: start free with 5 monitors or try the free tools.