Back to Knowledge Base

Setting Up Two-Factor Authentication for Your Company

Updated September 24, 2026

Setting Up Two-Factor Authentication for Your Company

This article is for Administrators and Company Admins.

Two-factor authentication (2FA) adds a critical second layer of security to every Attlock login. Even if a password is compromised, an attacker cannot access the account without the second factor. This guide walks you through enabling 2FA for your own account and enforcing it across your entire company.

Why 2FA Matters for Security Operations

Attlock company registration form with organization setup fields.
Company setup: enter your organization details to configure Attlock.

Security workforce management platforms hold sensitive data — guard locations, incident reports, client site details, and payroll information. Enforcing 2FA across your organization significantly reduces the risk of unauthorized access, credential stuffing attacks, and insider threats.

Enabling 2FA on Your Own Account

  1. Navigate to Settings → Security in the Attlock dashboard.
  2. Under Two-Factor Authentication, click Enable 2FA.
  3. Choose your preferred method:
    • Authenticator App (recommended) — works with Google Authenticator, Authy, or any TOTP-compatible app.
    • Email OTP — a one-time code sent to your registered email address.
  4. For authenticator apps, scan the QR code displayed on screen with your app.
  5. Enter the 6-digit code from your app to confirm setup.
  6. Save your backup codes — Attlock generates 10 single-use backup codes. Store these securely offline. They are the only way to recover access if you lose your device.

Enforcing 2FA Company-Wide

As a Company Admin or Super Admin, you can require all users in your organization to set up 2FA before they can access the dashboard.

  1. Go to Settings → Security → Company Security Policy.
  2. Toggle Require Two-Factor Authentication to On.
  3. Set the Grace Period — the number of days existing users have to enroll before being locked out (recommended: 7 days).
  4. Click Save Policy.

Once enforced, any user who has not set up 2FA will be redirected to the 2FA enrollment screen on their next login. They cannot access any other part of the dashboard until enrollment is complete.

Managing 2FA for Your Team

Viewing Enrollment Status

Go to Settings → Security → 2FA Enrollment to see a table of all users and their 2FA status:

StatusMeaning----------------EnabledUser has 2FA activePendingUser is within the grace periodNot EnrolledUser has not set up 2FA

Resetting a User's 2FA

If a guard or supervisor loses access to their authenticator device:

  1. Go to Team → Guards (or Settings → Users).
  2. Find the user and open their profile.
  3. Under Security, click Reset 2FA.
  4. Confirm the action — the user will be prompted to re-enroll on their next login.

Only Company Admins and Super Admins can reset another user's 2FA.

Supported 2FA Methods

MethodSecurity LevelBest For---------------------------------Authenticator App (TOTP)HighAll usersEmail OTPMediumUsers without smartphonesPasskey / BiometricVery HighAdmins and supervisors

Best Practices

  • Enforce 2FA before going live — set the policy during onboarding, not after.
  • Use authenticator apps over email OTP — email OTP is vulnerable to email account compromise.
  • Audit enrollment monthly — check the enrollment report to catch any users who have disabled 2FA.
  • Protect backup codes — treat them like passwords; do not store them in email or chat.

Related Articles

  • Access Control & Roles
  • Settings & Configuration
  • Invitations & Onboarding

Was this article helpful? Contact Support