Skip to main content

πŸ” How to Enable Two-Factor Authentication (2FA) for All Users

As an administration user, you can use this feature to add an extra security layer for all users in your organization. It requires them to enter a one-time password (OTP) code when logging in to Lucidya.

Updated over a week ago

Access Two-Factor Authentication Page


  1. Click the βš™οΈ Settings icon in the left sidebar. You must have Manager permission for the General Settings module.

  2. On the Settings page, click the "Security" tab.

  3. Click the "Enable" button under "Two-Factor Authentication For All Users."

Step 1: Enable 2FA For All Users


  1. A pop-up screen will appear asking you to select one or more methods to verify user identity in the first step:

    1. Email Verification: Send verification codes to users' emails.

    2. SMS Verification: Send codes via SMS to users' phone numbers (a paid service that requires a request to the customer success manager).

    3. Authenticator App: Send codes to users via the authenticator app.

  2. You can enable the "Remember me" option to reduce verification steps and save devices as trusted.

  3. Finally, click "Enable."

Step 2: Complete the Two-Factor Authentication Setup


In this step:

  1. You'll receive an email with the verification code.

  2. Copy the code, enter it, and click "Verify."

  3. A success message will confirm that two-factor authentication is enabled. An email with setup instructions will be sent to all existing users, who will need to enable authentication at their next login.

Disable & Edit Two-Factor Authentication


You can edit or disable 2FA, but we don't recommend doing so. Enabling 2FA adds an extra security layer that protects all users from attackers.

  • To disable 2FA: Click the "Disable" button and confirm the action. You'll receive an email with an OTP code. Copy and enter the code to disable this feature for all users.
    ​

  • To edit 2FA: Click the "Edit" button to change 2FA methods (Email, SMS, and/or Authenticator App) and confirm the action. You'll receive an email with an OTP code. Copy and enter the code to apply the changes for all users.
    ​

⁉️ FAQs


πŸ’‘ What is Two-Factor Authentication (2FA)?

Two-Factor Authentication (2FA) is a security feature that adds an extra layer of protection to user accounts. It requires users to provide two forms of verification when logging in: their password and a one-time code sent via email, SMS, or an authenticator app.

β›” Is 2FA mandatory for all users once enabled?

Yes, once you enable 2FA for all users in your organization, every user will be required to set it up during their next login. This ensures consistent security across your organization.

✨ What happens if a user doesn't receive the verification code?

If a user doesn't receive the verification code, they should:

  • Check their spam or junk email folder if using email verification

  • Verify their phone number is correct if using SMS verification

  • Ensure their authenticator app is properly configured

  • Contact your organization's administrator for assistance

πŸ” Can users choose their preferred 2FA method?

Users can only use the verification methods you enable as an administrator. If you enable multiple methods (Email, SMS, and/or Authenticator App), users can choose their preferred option from those available. For more information, check this guide: Set Up Two-Factor Authentication (2FA) for the First Time

βœ… What does the "Remember me" option do?

The "Remember me" option allows users to save their device as trusted. When enabled, users won't need to complete the 2FA verification process every time they log in from that specific device, reducing friction while maintaining security.

πŸ’¬ Is SMS verification included in my plan?

No, SMS verification is a paid service that requires a separate request to your customer success manager. Email verification and Authenticator App verification are included by default.

πŸ“© What happens to active user sessions when 2FA is enabled?

When you enable 2FA, all existing users will receive an email with setup instructions. They will be required to complete the 2FA setup process during their next login attempt.

β›” Can individual users disable 2FA for themselves?

No, individual users cannot disable 2FA once it's enabled for all users by an administrator. Only administrators with Manager permission for the General Settings module can disable or edit 2FA settings organization-wide.

Did this answer your question?