Skip to main content

Secure your account using Two-Factor Authentication (2FA)/Multi-Factor Authentication (MFA)

This article will guide you on how to set up 2FA/MFA for your Recruit CRM account.

Written by Sanjana Panigrahi

What this feature does and when to use it?

Two-Factor Authentication (2FA), or Multi-Factor Authentication (MFA), adds an additional layer of security to your Recruit CRM account by requiring a verification code from an authenticator app in addition to your username and password when signing in.

When 2FA is enabled, your Recruit CRM account is linked to an authenticator app using a QR code or setup key. The authenticator app generates a time-based, one-time six-digit verification code that must be entered during login.

When 2FA is enforced at the account level, all users are required to configure and use 2FA unless they have been specifically excluded. Users receive an email notification prompting them to complete the setup and can configure it during their next login.

Use this feature when:

• You want to add an extra layer of protection to your Recruit CRM account

• Your organization has security or compliance requirements that mandate 2FA or MFA.

• You need to enforce 2FA for all users, or all users except selected individuals.


How to set up Two-Factor Authentication?


1. To set up 2FA/MFA for your account, click on your Profile icon in the top-right corner of Recruit CRM and select Profile.
​


2. Next, navigate to the Security tab.

Once you are in the Security tab, turn on the Authentication App toggle to begin the 2FA/MFA setup process.


​3. The system will immediately open a pop-up with a QR Code to set up the authentication process. You can either:

  • Download an authenticator app like Authy, Google Authenticator, 1Password, or Microsoft Authenticator from your mobile app store and scan the QR code.

  • Manually enter the given code into the authenticator app.

4. Once you connect your Recruit CRM account to the security or authentication app, you'll get a one-time verification code whenever you need it.

5. Insert the 6-digit code and select the "Enable Two Factor Authenticator" option.
​

6. You will then need to sign out of your account and log in again to set up Two-Factor Authentication. Enter both your password and a security code from your authenticator app to sign in to your account.

​


How to enforce 2 Factor Authentication for all users


Users with permission to Account settings can enforce 2FA for all users and enhance security across the organization.

1. Go to Account on the Admin Settings to enforce the Two-Factor Authentication. You will get the option to make it required for all account users or to exclude specific users.
​


​If you choose to exclude specific users, you'll see a list of all current teammates in your account, and you can select the ones you wish to exclude.
​

2. After enforcing the Two-Factor Authentication, users will get an email to configure it and will have the option to set it up during their next login in Recruit CRM.
​


🚫 How to disable Two-Factor Authentication


  • If 2FA is not mandatory in your account, you can disable it from the Security tab in your Profile Settings by entering your Recruit CRM password.
    ​

  • In case a user is locked out of their account and 2FA is enforced, anyone with access to User Management settings can disable the 2FA option and allow the teammate to log into Recruit CRM.
    ​

  • You can quickly identify the Two-Factor Authentication status by checking the column. There are three possible statuses:

Disabled

2FA is not enabled by the user

Enabled

2FA was enabled by the user

Enforced

2FA is mandatory for that specific user

Enabling MFA will disable SSO if that is enabled on the account.


Troubleshooting


Problem: I cannot log in because I do not have access to my authenticator app.

Likely cause: 2FA is enabled (or enforced), and you no longer have your device or app configured.

What to check: Check whether 2FA is enforced on your account and whether someone in your organization has user management access.

Resolution: Contact a user with user management settings access so they can disable 2FA for your user account. Once you regain access, you can set up 2FA again.

Problem: I am not sure what the 2FA status values mean in the user list.

Likely cause: The meaning of Disabled, Enabled, and Enforced is unclear.

What to check: Look at the 2FA status column for each user.

Resolution: Use these definitions:
Disabled = 2FA is not enabled
Enabled = user turned on 2FA
Enforced = 2FA is mandatory for that user.


FAQs


Who can enforce two-factor authentication for all users?

Users with permission to account settings can enforce 2FA for all users.

Can I exclude specific users from enforced 2FA?

Yes. In the Account settings, after enabling the enforce option, you can choose to exclude specific users and select those you do not want to enforce 2FA for.

How can I see whether a user has 2FA enabled or enforced?

In the user management, check the 2 Factor Authentication status column. It will show one of three statuses: Disabled, Enabled, or Enforced.

Does enabling multi-factor authentication affect SSO?

Yes. Enabling multi-factor authentication will disable SSO if SSO is enabled on your account.

Conclusion:

Two-factor authentication in Recruit CRM helps protect your account and your organization by adding a secure verification step to the login process.

Hope this helps!

Did this answer your question?