MULTI-FACTOR AUTHENTICATION (MFA) FOR ENTERPRISE ACCOUNTS
This feature will be fully available on August 6, 2026.
Enterprise accounts can now require multi-factor authentication (MFA) for users when signing in. Administrators can enable or disable MFA at the account level and designate machine-to-machine (M2M) users for API use with access tokens.
Note: When MFA is enabled at the account level, all non-M2M users must use MFA.
When MFA is enabled, users are guided through a first-time enrollment process using supported authenticator applications, including Google Authenticator and Okta Verify. The enrollment experience includes QR code setup, verification code validation, and a self-service option for replacing an enrolled device.
We also improved the sign-in experience with streamlined MFA prompts and status indicators throughout the authentication process.