Skip to main content

Security Policies

Set organization-wide rules for how members authenticate, under Organization settings → Security. Changes here apply to everyone in your organization.

SettingWhat it does
Enforce MFARequires every member to enroll a second factor before they can use the dashboard
MFA exempt domainsSkip the MFA requirement for members whose email matches specific domains, useful for a domain that's fully covered by SSO with its own MFA
Allowed factorsChoose which second factors members can enroll: one-time passcodes, security keys (WebAuthn), or both

Members manage their own factors under Profile & MFA. This page only controls what your organization requires and allows.