Skip to main content

Two-Factor Authentication (MFA)

Require a second check at sign-in for everyone in your organization, and what your team sees when it is on.

Written by Austin Carroll

Two-factor authentication (also called multi-factor authentication, or MFA) adds a second check when people sign in to Warrant with a password. When an admin turns it on, a correct password is no longer enough on its own: Warrant also emails the person a single-use link to confirm it is really them. This article covers how admins turn it on and what everyone else sees at sign-in.

Turn on two-factor authentication (admins)

The setting applies to everyone in your organization at once.

  1. Click Settings at the foot of the workspace sidebar.

  2. Under Members, select Access & security.

  3. In the Sign-in card, switch on Multi-factor authentication (MFA).

You will see a confirmation that MFA is enabled for your organization. To turn it off again, switch it off in the same place. Companies that leave the setting off see no change at sign-in.

Tip: in Settings, you can also type mfa or 2fa into the search box to jump straight to this switch.

What your team sees at sign-in

Once the setting is on, signing in with an email and password works like this:

  1. Enter your email and password on the Warrant login page as usual.

  2. Instead of going straight in, you see: "For your security, we've sent a verification link to your email. Please click the link to complete your login."

  3. Open the email from Warrant and click the link. The link works once and expires after 15 minutes.

  4. On the Verify your login. page, leave Trust this device for 30 days ticked if you are on your own computer, or untick it on a shared one.

  5. Click Complete Login. You are signed in and taken into Warrant.

If you trusted the device, you will not be asked again on that browser for 30 days. Signing in from a new browser, a private window, or after clearing your cookies will send a fresh link.

When you will not be asked

  • Google and Microsoft sign-in. If you use Continue with Google or Continue with Microsoft, Warrant does not send an email, because your Google or Microsoft account already provides the second check.

  • Right after accepting an invitation or resetting your password. Both of those already prove you can reach your inbox, so Warrant does not challenge you again straight afterwards.

  • On a trusted device within its 30 days.

Troubleshooting

  • The link has expired or already been used. Go back to the login page and sign in again to get a new link. Only the most recent link works.

  • The email has not arrived. Check your spam or junk folder and any quarantine your IT team uses. If you have requested several links in a short time, wait a few minutes before trying again.

  • You can no longer reach your email inbox. The second check goes to the email address on your Warrant account, so contact your Warrant admin. If you have Google or Microsoft sign-in for the same address, you can use that instead.

  • You forgot your password. Use Forgot your password? on the login page. See How to Reset Password.

Who can use it

Only admins can see and change the Multi-factor authentication (MFA) switch. Once it is on, it applies to every member of the organization who signs in with a password.

For other sign-in protections, see Anomalous Login Detection.

Did this answer your question?