Two-Factor Authentication: Reset and Enforcement
What are Two-Factor Authentication Reset and Enforcement?
Two-Factor Authentication (2FA) asks a person for a code from their authenticator app on top of their password. Two account-level controls sit around it.
Reset clears someone's 2FA when they have lost the device it lives on, so they can sign in again and set it up afresh. Without it, a lost phone locks that person out and nobody in the account can help.
Enforcement lets you require 2FA rather than leave it to each person. You can require it for your Staff Targets, for your CRM Targets, or for both, and see at a glance who is set up and who is not.
Resetting works on every plan. Enforcement is part of the PLUS Power-Up.
TIP: Everyone sets up and manages their own 2FA on the My Account > Security page. CLICK HERE to learn how to turn 2FA on.
How do I reset someone's 2FA when they have lost their device?
Open the person's record, choose Reset Two-Factor Authentication, and confirm with your own password. It is done immediately. There is no support ticket and no waiting on SuiteDash.
The option lives in two places:
- For a Staff Target: in the row actions on your Staff list.
- For a CRM Target: in the row actions on your Contacts list, and in the Action Items sidebar on their Manage Profile.
It only appears for people who actually have 2FA turned on, so if you cannot see it, there is nothing to reset.

Resetting works downward through the role hierarchy. A Super Admin can reset Admins and everyone below, and an Admin can reset everyone below Admin. Nobody can reset a peer and nobody can reset upward, so the people who can unlock an account always outrank it.
TIP: A reset removes a protection, it never grants access. Even after a reset, that person still needs their own password to log in. You are asked for your password precisely because clearing someone's second factor is a security-affecting action that should carry a little weight.
IMPORTANT: You cannot reset someone's 2FA while you are impersonating another user. Exit impersonation first. Too many incorrect password attempts will also lock resetting for 24 hours.
What does the person whose 2FA was reset experience?
The affected person is always emailed the moment their 2FA is reset. The email states that the reset happened and when, and tells them to contact their account admin if they did not request it. It does not name who performed the reset, and it carries no link and asks for nothing, so an unexpected copy is safe to receive and obvious to question. This notification cannot be switched off.
On their next sign-in they log in with just their password. When enforcement is off, setting up a new authenticator is their choice and they can do it whenever they are ready. When 2FA is required, they are guided into setting it up with a fresh compliance window.
IMPORTANT: Every reset is also recorded permanently in the activity stream, naming who performed it and when. That record is visible to Admins and Super Admins only, never to the affected person or to other users. Neither the record nor the email can be turned off.
What if a Super Admin loses their device?
Because resets only work downward, a Super Admin has nobody above them. For that reason, a Super Admin receives a set of ten one-time Recovery Codes when they turn on 2FA. The codes are shown once and cannot be shown again, so save them somewhere that is not the phone. If a Super Admin loses their device, a recovery code gets them back in, and they can then clear and set up their 2FA again.

Each code works once, in place of the 6-digit code from the authenticator app. At the two-factor prompt there is a Lost your phone? Use a recovery code link. Spending a code emails the account holder and tells them how many they have left, and a fresh set is issued the next time they set up 2FA.
TIP: Recovery Codes are provided for Super Admins only, because every other role already has a faster path: an Admin who can reset them in seconds.
How do I require 2FA for my account?
Go to Organization Settings and find the Enforce Two-Factor Authentication section, just beneath Enforce Secure Password. There are two independent switches, so you can require 2FA for your internal Staff Targets, for your CRM Targets, or for both. These are genuinely separate decisions, made separately.

Require it for Staff Targets applies to everyone on your internal team. Require it for CRM Targets applies to every CRM Target who signs in to your Client Portal, which means Clients, Leads, Prospects and External Users. A CRM Target with no portal login is not affected.
You also set a Compliance Window, the number of days people have to set up 2FA before it is needed to sign in. Presets run from Immediate through 3, 7, 14 and 30 days, you can type any value up to 365, and the default is 14 days. Everyone in the account today shares the same deadline, counted from the day you switch a requirement on. People who join later get their own window starting the day they arrive, and so does anyone whose 2FA was just reset.
TIP: Choosing Immediate asks you to confirm first, and tells you how many people it would stop from signing in. It is a legitimate choice, just never an accidental one.
IMPORTANT: A requirement will not switch on until the Super Admin it covers is already set up with 2FA and has saved their Recovery Codes. This is a hard gate, not a warning, so you cannot accidentally lock out the one account nobody can rescue. Until then the switches are held and the section tells you who it is waiting on, with a button to remind them.
IMPORTANT: Enforcement is part of the PLUS Power-Up. If the Power-Up lapses, the requirement stops and you are emailed about it, but nobody loses the 2FA they already set up and your settings are kept. If the Power-Up is restored, the requirement picks up again and everyone still unprotected gets a full window.
How do I see who is protected?
The Who Is Set Up group at the bottom of the section shows how many of your Staff Targets and CRM Targets have 2FA active. Open the full list from either View List link to see each person, their role, and whether they are set up or still need to.

The panel opens filtered to Not Set Up, since that is the list you usually want, and you can switch to Active or Everyone, search by name, and move between Staff Targets and CRM Targets. Each person who is not set up has a Remind action that emails them, and Remind Everyone Not Set Up at the bottom does the whole group at once. Anyone reminded in the last day is skipped.
What happens to people who have not set up 2FA yet?
While a requirement is on, anyone without 2FA sees a banner across the Portal counting down the days they have left, with a Set it up now button that takes them straight to their Security page. They can carry on working until their window closes.
Once the window closes, every page sends them to My Account > Security until they set it up. They are never removed from the account and never stripped of any access, they are simply guided through setup first. Turning a requirement back off later leaves everyone's existing 2FA in place and simply stops the prompting.
IMPORTANT: While a requirement covers someone, they cannot switch their own 2FA off. If they have lost their device, an Admin resets it for them, which gives them a fresh window to set it up again.
CLICK HERE to learn more about Organization Settings.