Security Policies
Set organization-wide rules for how members authenticate, under Organization settings → Security. Changes here apply to everyone in your organization.
| Setting | What it does |
|---|---|
| Enforce MFA | Requires every member to enroll a second factor before they can use the dashboard |
| MFA exempt domains | Skip the MFA requirement for members whose email matches specific domains, useful for a domain that's fully covered by SSO with its own MFA |
| Allowed factors | Choose which second factors members can enroll: one-time passcodes, security keys (WebAuthn), or both |
Members manage their own factors under Profile & MFA. This page only controls what your organization requires and allows.