This reference article covers what to do when things go wrong, explains behavioral edge cases, and lists permissions and audit logging details relevant to both admins and users.
What to Do If Your Email Bounces
If a verification code email cannot be delivered to you, a red notification will appear on the verification screen. Contact your Company Admin to resolve the issue. Once unblocked, click Resend Code to request a new verification code.
Account Lockout
If you enter the wrong verification code 5 times on the login page, your account will be locked. Contact your Company Admin or System Admin to unlock it. An email notification is sent to your admin automatically.
Remember Device Behavior
Scenario | Result |
User enabled 2FA only from Profile Settings | Remember Device is shown by default on login. |
Admin enabled company-wide 2FA with Remember Device OFF | Remember Device is NOT shown, overriding the user's profile default. |
Admin enabled company-wide 2FA with Remember Device ON | Don't ask again for 7 days checkbox appears on login. |
Cancelling During Verification
If a user starts a verification process (e.g. enabling 2FA) and clicks Cancel before submitting a code, they must wait 1 minute before re-initiating the process. This prevents excessive verification code requests.
2FA Setup Reset Scenarios
A user's 2FA setup is reset in the following situations:
The company admin disables company-wide 2FA.
The user disables their own 2FA.
The user had email 2FA enabled, but the admin later enforces 2FA without including the email method.
The user had SMS enabled, but the admin removes the company's SMS package.
Failed Verification Attempt Limits — Summary
Context | Attempts | Outcome |
Admin: Enabling 2FA | 5 | Process paused; Enable button disabled with retry tooltip. |
Admin: Disabling 2FA | 5 | Process paused; Disable & Edit buttons disabled with retry tooltip. |
Admin: Editing 2FA | 5 | Process paused; Disable & Edit buttons disabled with retry tooltip. |
User: Enabling 2FA (Profile) | 5 or 10 total OTP requests | Process paused; button disabled. Account NOT locked. |
User: Disabling 2FA (Profile) | 5 or 10 total OTP requests | Process paused; Disable button disabled. Account NOT locked. |
User: Login page | 5 or 10 total OTP requests | Account locked. Admin notified by email. |
Audit Logging
All 2FA-related actions are recorded in the system activity log, including:
Enabling, disabling, and editing company-wide 2FA (admin).
Enabling, disabling, and editing individual 2FA (user profile).
Requesting the SMS verification package upgrade.
Permission Requirements
Action | Required Permission |
Enable / Disable / Edit company-wide 2FA | Manager — General Settings |
View & manage Bounced Emails | Manager — General Settings |
Enable / Disable personal 2FA | Any authenticated user |
Unlock suspended accounts | System Administrator |
