Multi-factor authentication (MFA), sometimes called two-factor authentication (2FA) adds an extra layer of security beyond just a password, making it significantly harder for attackers to gain unauthorized access even if the password were compromised.
Enforcing MFA helps protect sensitive data, customer accounts, and internal systems from common threats like phishing and credential stuffing. MFA is available to all users on all plans.
Many business insurance policies now require that MFA be used if available and our platform supports that, you can decide as a business to enforce it for all users. We recommend having a consistent policy for MFA, and which method you use, across your business.
Enforcement
As an organisation admin you can decide if you want to require your users to have MFA setup whenever they login. To enable MFA for all users, view your organsiation settings.
Available options
Passkeys
Security keys
Biometrics
One-time passcodes
You can go further and enable SSO using Google or Microsoft, this requires more configuration to get setup.
Helping users login
If a user loses access to their MFA, an organisation admin can remove the existing MFA from the user and the user will be prompted to add them again next time they login.
The Glu support team cannot assist a user bypassing or removing MFA.
