Manage two-factor authentication for a user
How to make two-factor authentication mandatory for a single account in preeco | hinweisgeber, roll it out across the whole team, and reset an existing 2FA setup after a lost device.
In preeco | hinweisgeber you decide per account whether a person must sign in with a second factor. This guide shows how to enforce 2FA for a team member, roll the requirement out across the team, and reset an existing two-factor setup.
Prerequisites
- You have the
editpermission for the Users module. - The account already exists in the team. For a new invitation you can set the requirement right away (see the final section).
- The “Reset two-factor authentication” button is only visible if the person has already set up 2FA.
Enforce 2FA for one account
- Go to “Settings → Users” and open the detail page of the person concerned.
- Switch to the “Two-factor authentication” tab. The “Enforce two-factor authentication” field shows the current value “Yes” or “No”.
- Click “Edit”. A side panel opens with the title “Two-factor authentication”, showing the person's name or email address as its heading.
- Tick the “Enforce two-factor authentication” checkbox. To lift the requirement, clear the checkbox instead.
- Click “Save”. The side panel closes and the tab shows the updated value.
To discard the change, click “Cancel” or close the side panel.
If the requirement is active and the person has not set up 2FA yet, they are prompted to do so at their next login. Until then, access to the application stays blocked.
Roll the requirement out across the team
There is no team-wide bulk setting — the requirement is set per account. Work through the overview to complete the rollout:
- Open “Settings → Users”.
- Set the “Two-factor authentication” filter to “Disabled”. You now see every account still missing the requirement.
- Enforce 2FA for each of these accounts as described above.
- Check the result in the “Two-factor authentication” column of the overview.
Reset an existing 2FA setup
- Open the side panel as described in steps 1 to 3 above.
- Click “Reset two-factor authentication”.
- Confirm the “Reset two-factor authentication” dialog with “Reset”. The two-factor information is deleted and cannot be restored.
At their next login, a setup wizard guides the person through configuring 2FA again, provided the requirement is active.
Practical tips
- Use the reset when someone has lost their mobile device or can no longer access their authenticator app — the prompt to set 2FA up again follows automatically.
- For new accounts, tick “Enforce two-factor authentication” directly in the “Invite users” side panel so the requirement applies from the very first login.
Changes and errors may occur. The information in this article has been carefully compiled, but does not claim to be complete or correct.