Skip to main content

2FA: Troubleshooting, Edge Cases & Permissions

This reference article covers what to do when things go wrong, explains behavioral edge cases, and lists permissions and audit logging details relevant to both admins and users.

What to Do If Your Email Bounces

If a verification code email cannot be delivered to you, a red notification will appear on the verification screen. Contact your Company Admin to resolve the issue. Once unblocked, click Resend Code to request a new verification code.

Account Lockout

If you enter the wrong verification code 5 times on the login page, your account will be locked. Contact your Company Admin or System Admin to unlock it. An email notification is sent to your admin automatically.

Remember Device Behavior

Scenario

Result

User enabled 2FA only from Profile Settings

Remember Device is shown by default on login.

Admin enabled company-wide 2FA with Remember Device OFF

Remember Device is NOT shown, overriding the user's profile default.

Admin enabled company-wide 2FA with Remember Device ON

Don't ask again for 7 days checkbox appears on login.

Cancelling During Verification

If a user starts a verification process (e.g. enabling 2FA) and clicks Cancel before submitting a code, they must wait 1 minute before re-initiating the process. This prevents excessive verification code requests.

2FA Setup Reset Scenarios

A user's 2FA setup is reset in the following situations:

  • The company admin disables company-wide 2FA.

  • The user disables their own 2FA.

  • The user had email 2FA enabled, but the admin later enforces 2FA without including the email method.

  • The user had SMS enabled, but the admin removes the company's SMS package.

Failed Verification Attempt Limits — Summary

Context

Attempts

Outcome

Admin: Enabling 2FA

5

Process paused; Enable button disabled with retry tooltip.

Admin: Disabling 2FA

5

Process paused; Disable & Edit buttons disabled with retry tooltip.

Admin: Editing 2FA

5

Process paused; Disable & Edit buttons disabled with retry tooltip.

User: Enabling 2FA (Profile)

5 or 10 total OTP requests

Process paused; button disabled. Account NOT locked.

User: Disabling 2FA (Profile)

5 or 10 total OTP requests

Process paused; Disable button disabled. Account NOT locked.

User: Login page

5 or 10 total OTP requests

Account locked. Admin notified by email.

Audit Logging

All 2FA-related actions are recorded in the system activity log, including:

  • Enabling, disabling, and editing company-wide 2FA (admin).

  • Enabling, disabling, and editing individual 2FA (user profile).

  • Requesting the SMS verification package upgrade.

Permission Requirements

Action

Required Permission

Enable / Disable / Edit company-wide 2FA

Manager — General Settings

View & manage Bounced Emails

Manager — General Settings

Enable / Disable personal 2FA

Any authenticated user

Unlock suspended accounts

System Administrator

Did this answer your question?