Setting Up Two-Factor Authentication for Your Company
This article is for Administrators and Company Admins.
Two-factor authentication (2FA) adds a critical second layer of security to every Attlock login. Even if a password is compromised, an attacker cannot access the account without the second factor. This guide walks you through enabling 2FA for your own account and enforcing it across your entire company.
Why 2FA Matters for Security Operations

Security workforce management platforms hold sensitive data — guard locations, incident reports, client site details, and payroll information. Enforcing 2FA across your organization significantly reduces the risk of unauthorized access, credential stuffing attacks, and insider threats.
Enabling 2FA on Your Own Account
- Navigate to Settings → Security in the Attlock dashboard.
- Under Two-Factor Authentication, click Enable 2FA.
- Choose your preferred method:
- Authenticator App (recommended) — works with Google Authenticator, Authy, or any TOTP-compatible app.
- Email OTP — a one-time code sent to your registered email address.
- For authenticator apps, scan the QR code displayed on screen with your app.
- Enter the 6-digit code from your app to confirm setup.
- Save your backup codes — Attlock generates 10 single-use backup codes. Store these securely offline. They are the only way to recover access if you lose your device.
Enforcing 2FA Company-Wide
As a Company Admin or Super Admin, you can require all users in your organization to set up 2FA before they can access the dashboard.
- Go to Settings → Security → Company Security Policy.
- Toggle Require Two-Factor Authentication to On.
- Set the Grace Period — the number of days existing users have to enroll before being locked out (recommended: 7 days).
- Click Save Policy.
Once enforced, any user who has not set up 2FA will be redirected to the 2FA enrollment screen on their next login. They cannot access any other part of the dashboard until enrollment is complete.
Managing 2FA for Your Team
Viewing Enrollment Status
Go to Settings → Security → 2FA Enrollment to see a table of all users and their 2FA status:
| Status | Meaning | -------- | -------- | Enabled | User has 2FA active | Pending | User is within the grace period | Not Enrolled | User has not set up 2FA |
|---|
Resetting a User's 2FA
If a guard or supervisor loses access to their authenticator device:
- Go to Team → Guards (or Settings → Users).
- Find the user and open their profile.
- Under Security, click Reset 2FA.
- Confirm the action — the user will be prompted to re-enroll on their next login.
Only Company Admins and Super Admins can reset another user's 2FA.
Supported 2FA Methods
| Method | Security Level | Best For | -------- | --------------- | ---------- | Authenticator App (TOTP) | High | All users | Email OTP | Medium | Users without smartphones | Passkey / Biometric | Very High | Admins and supervisors |
|---|
Best Practices
- Enforce 2FA before going live — set the policy during onboarding, not after.
- Use authenticator apps over email OTP — email OTP is vulnerable to email account compromise.
- Audit enrollment monthly — check the enrollment report to catch any users who have disabled 2FA.
- Protect backup codes — treat them like passwords; do not store them in email or chat.
Related Articles
- Access Control & Roles
- Settings & Configuration
- Invitations & Onboarding