SECURITY
Set up multi-factor authentication (MFA)
MFA adds a second verification step beyond the password. This article shows how to enable it for yourself and enforce it across the organization.
How MFA works
After the password, Apus asks for a one-time code from an authenticator app. Even if a password leaks, an attacker can't sign in without the second factor.
Enable for your account
- Go to Account → Security.
- Choose 'Enable MFA' and scan the QR code with an authenticator app.
- Enter the 6-digit code to confirm.
- Save the recovery codes somewhere safe.
Enforce org-wide
Admins can require MFA for all users or for specific roles (e.g. finance, admins) under Admin → Security policy. Users without MFA are prompted to set it up at next sign-in.
Recovery
If a user loses their device, an admin can reset their MFA enrolment; the user then re-registers a new authenticator. Every reset is recorded in the audit log.
TIP
Enforce MFA at least for admin and finance roles, even if you don't require it org-wide yet.
Was this article helpful?