Two-factor authentication provides an extra layer of security by mandating an additional authentication method along with passwords.
Role required: SDAdmin/all users (for single-instance setups) and SDOrgAdmin (for multi-instance setups).
To enable two-factor authentication,
Users must authenticate themselves with the code sent to their email. The email verification template is customizable. In the email text, you can use $secretCode, which will be replaced by a unique code each time the email is sent to the users.
For email verification to work, the outgoing mail server must be configured. Learn more.
Users can customize email verification messages for application login, sensitive operations, and approval actions (portal-specific).

Users must authenticate themselves using the code sent to their email. The email verification template is customizable. In the email text, you can use $secretCode, which will be replaced by a unique code each time the email is sent to the users.
Users must verify themselves with a time-based OTP (TOTP) generated by the Google Authenticator app or any TOTP authenticator app, such as Microsoft Authenticator or Duo Mobile. etc.
Enable this option to prompt users to authenticate during login.
You can enable TFA for specific users or user types. Hover over criteria fields and click Edit to open the fields in an editable format.
to view all users in a pop-up for selection.
icons.

When two-factor authentication is enabled, users must enroll themselves during their first login. Learn more.
Backup codes can be enabled only for user logins. Enabling backup verification codes allows users to view, download, or generate codes that can be used as an alternative to any of the authentication methods. Learn more.
Enabling this option prompts the admin to authenticate themselves while modifying settings under Admin
.
Two-factor authentication can be enabled for the following admin configurations:
When this option is enabled, the admin must enroll for two-factor authentication during their first login. Learn more.
Enable TFA Trust to establish a time frame during which the admin can modify settings without re-authentication.

You can manage users who have enrolled for two-factor authentication under Admin > General Settings > Two Factor Authentication > Enrolled Users (for single instance setups) or ESM Directory > Two Factor Authentication > Enrolled Users (for multi-instance setups).
Here, you can view details such as username, domain name, and authentication type. Additionally, you can also delete user enrollments by selecting one or more users and clicking Delete.

Two-factor authentication (TFA) adds an extra layer of security for portal-specific sensitive admin configurations (SDAdmins, HelpDesk Admins, OrgAdmins), and module approval actions by requiring verification via OTP.
Enable Two-Factor Authentication for Sensitive Operations: When this option is enabled, portal-specific sensitive admin configurations and module approval actions are listed.
.png?Policy=eyJTdGF0ZW1lbnQiOlt7IlJlc291cmNlIjoiaHR0cHM6Ly9kemY4dnF2MjRlcWhnLmNsb3VkZnJvbnQubmV0L3VzZXJmaWxlcy84NjYvMTQyNjIvY2tmaW5kZXIvaW1hZ2VzL3F1LzIwMjYvdW5rbm93big0MykucG5nIiwiQ29uZGl0aW9uIjp7IkRhdGVMZXNzVGhhbiI6eyJBV1M6RXBvY2hUaW1lIjoxNzkwMjY5MDYxfX19XX0_&Signature=d7kTdHtQMA2UlqRxADfZuSM1TR8zu46b~B-Mgpr4fsMWNYu2nJsfgltnfpoDQpteKLKH4mZth3ijg~8BnYzmsTubw3jG3DRqCM8vvb6DlV4UN2zeHz05nOX7EudHDOqenU1T5WigN4fw093amfEZHISNWiisSLXtWNMZO3Tf2slTEcElAq4mX5M3mLJZ7b0kSG-53kYMKPvcXJKtBkR8LBqsk9inYXm8KjROdED7PnY7MROggPydEEYjsd~eYfzm66G04Sn0a7E~Ax-jGM5~uXIOCkT3po13utOrEdlLQPXEZHeeUj8s-9d5QCaZvXam4UynjwuAYEaPuuJw6iLw8w__&Key-Pair-Id=K2TK3EG287XSFC)
.
.

.png?Policy=eyJTdGF0ZW1lbnQiOlt7IlJlc291cmNlIjoiaHR0cHM6Ly9kemY4dnF2MjRlcWhnLmNsb3VkZnJvbnQubmV0L3VzZXJmaWxlcy84NjYvMTQyNjIvY2tmaW5kZXIvaW1hZ2VzL3F1LzIwMjYvdW5rbm93big0NCkucG5nIiwiQ29uZGl0aW9uIjp7IkRhdGVMZXNzVGhhbiI6eyJBV1M6RXBvY2hUaW1lIjoxNzkwMjY5MDYxfX19XX0_&Signature=GAv6PjoeyANOse5Jjznc773RlxiFqvLhpXXCggD8NWz3ugghlAYmSoTmcAVSxqpZN18CqIIAMtSXN18d-U7rqiLh1XpKkqjFegLfy2jSlihpEdTlmH3rIq5Iz2f693uNXg8f2~tl3xWOug1oVQPiq~V0fTf6OhN2QAVgA8PegfCuby-ZxpvqLc8hnCznul67pl4WIIujnSRXMucGBQC6zUC24qAB961vDJOGRhDG9EkQY5AApgNhbLo1jiPUb-3aDxA88P55-tIMGqUSk0tHHIOhD0yjmRhCh7Zi-mR7Z6ZSARNoV~hc~ijagbfVOmYAuPwTUv0MPAeIgzCG1PE4Cg__&Key-Pair-Id=K2TK3EG287XSFC)
Portal Admins will be able to configure the interval period for reauthentication.
All TFA-verified operations will be bypassed in this portal during the reauthentication interval.
.png?Policy=eyJTdGF0ZW1lbnQiOlt7IlJlc291cmNlIjoiaHR0cHM6Ly9kemY4dnF2MjRlcWhnLmNsb3VkZnJvbnQubmV0L3VzZXJmaWxlcy84NjYvMTQyNjIvY2tmaW5kZXIvaW1hZ2VzL3F1LzIwMjYvdW5rbm93big0MikucG5nIiwiQ29uZGl0aW9uIjp7IkRhdGVMZXNzVGhhbiI6eyJBV1M6RXBvY2hUaW1lIjoxNzkwMjY5MDYxfX19XX0_&Signature=Eu8NMsP9BFcgBzTwNYa3W1ihktO64ltXLZ0MHYywKd~7ZZS5l2m6KydKzHp20WsmmkwXyUaWe4JiOoNbtu7ARXnB1vUs6WQkHD9aGKC~wJ9J~Ohvmq-j50f7X97dYkqx8pLoVDlR417~9g~hAFTONPHaXO44Jxugc1JU27mqY6JATkXjQ2h7NKUTbeWPHv6Kz9VWFrwkySR0ONvhm0selECSMf4usMTPw6t9tTdPI2KtN3tYrpoJnpRsbA4XiQ59nC46feA5AI~aI7OxPfbj-lgwzRRRYGcBKxSy75Pl2mmsgQQcsyuJf~~~47XbsdtvPGw0GYCH47HO-IxyhZfX7Q__&Key-Pair-Id=K2TK3EG287XSFC)