Two-factor authentication (2FA) is not available for projects using Single Sign-On (SSO) or access via passkeys.
2FA adds an extra layer of security by sending a short-term, updated password to each staff member when they try to log in.
To set up two-factor authentication, go to the Settings tab → Security → Security Policy.
To access the page, staff members need one of the following permissions:
View security settings
Manage security policy: full access
Authentication settings
Password expiration — the period during which the account password can be used for login. You can choose a duration starting from 1 day.
Two-factor authentication — choose SMS or Email.
Note: SMS authentication is not supported for phone numbers from the following countries:
Vietnam (+84), Haiti (+509), Democratic Republic of the Congo (+243), Egypt (+20), Indonesia (+62), Iraq (+964), Iran (+98), Qatar (+974), China (+86), Cuba (+53), Kuwait (+965), Laos (+856), Lebanon (+961), Madagascar (+261), Morocco (+212), Niger (+227), United Arab Emirates (+971), Oman (+968), Pakistan (+92), Saudi Arabia (+966), Thailand (+66), Tanzania (+255), Uganda (+256), Chad (+235)
Two-factor authentication applies to all staff on the project. It cannot be set up per user.
The options Hide customer personal data and Maestra staff access can only be edited if the Advanced security mode is enabled.

