| Overview |
As an Owner or Admin, you can control whether two-factor authentication (2FA) is optional or mandatory for all members of your organisation. Making 2FA mandatory ensures every member must set it up before they can access BrightHub or any associated products.
| Before You Begin |
- You must have Owner or Admin permissions.
- Changes to the organisation-wide 2FA setting apply to all members, regardless of their individual role.
| How to Set 2FA as Mandatory for Your Organisation |
- Log in to BrightHub and go to Members from the left-hand navigation.
- Click the 2FA Settings button on the right-hand side of the Members page.
- A window will appear with two options:
- Optional (default) — members can choose whether to enable 2FA themselves.
- Required — all members must set up 2FA the next time they log in.
- Select Required and confirm your choice.
| ⚠ Important: Once 2FA is set to Required, it applies immediately. The next time any member logs in — to BrightHub or any product purchased through BrightHub — they will be prompted to set up 2FA before they can proceed. |
| What Happens When a Member Logs In After 2FA is Enforced |
When a member logs in for the first time after 2FA has been set to Required, they will be presented with the 2FA setup screen. The default method will be set to Email. The member can:
- Complete setup using the email method immediately
- Choose a different method (SMS or authenticator app) during setup or change it later from their profile
They will not be able to access BrightHub or any associated products until 2FA setup is complete.
| ✔ Tip: If a member cannot complete the 2FA setup — for example, they do not have access to their email — an Admin or Owner can reset their 2FA method from the Members page. |
| Can 2FA Be Turned Off for the Organisation? |
No. Once mandatory 2FA is enabled at the organisation level, individual members cannot disable it. They can change the method they use — for example, switching from email to an authenticator app — but they cannot remove the 2FA requirement entirely.
If you change the organisation setting back to Optional, members who have already set up 2FA will keep it enabled on their accounts.
| Frequently Asked Questions |
Q: Will existing members be logged out when I enable mandatory 2FA?
A: No. Existing sessions are not affected immediately. The 2FA setup prompt will appear the next time each member logs in.
Q: Can I exempt specific members from the mandatory 2FA requirement?
A: No. The mandatory 2FA setting applies to all members of the organisation without exception.
Q: What if a member is unable to set up 2FA?
A: An Admin or Owner can reset their 2FA method from the Members page — select Manage next to their name and choose Reset 2FA to assign them a different method.
Comments
0 comments
Article is closed for comments.