Skip to main content

Organization Settings: Multi-Factor Authentication

Note: MFA can only be enabled for the entire account by an agent with the appropriate permissions. MFA settings can only be managed by your organization by an agent with the appropriate administrative permissions.

MFA is configured at the account level and may be required for all users, including users on new accounts during implementation. For security reasons, MFA cannot be disabled unless SSO with SAML is enabled.

For MFA, Alloy supports SMS for US numbers and time-based one-time passwords (TOTP). We recommend using TOTP with an authenticator app such as Microsoft Authenticator or Authy.

Setting up MFA

  1. Navigate to Settings > Authentication.

  2. In the Other Configuration section, select the three-dot menu.

  3. Select Edit Other Configuration.

  4. Select Multi-Factor Authentication Required.

  5. Select Confirm.

Once enabled, agents with MFA configured are prompted to enter a code from SMS or their authenticator app. Agents without MFA configured are prompted to set up MFA before they can complete login.

Before enabling MFA, confirm that each agent has the correct phone number or authenticator access so they can sign in.

Resetting MFA

An account administrator can reset an agent’s MFA enrollment if the agent loses or changes their phone or loses access to their authenticator. Alloy support is unable to reset MFA due to compliance reasons.

  1. Navigate to Settings > Agents.

  2. Locate the agent.

  3. Select the gear icon on the right.

  4. Select Reset MFA.

Reduce login interruptions during implementation testing

MFA cannot be disabled when the account’s security requirements mandate MFA or SAML SSO. If the goal is to reduce interruptions while testing, Alloy Support can increase the account’s session duration.

Increasing session duration may reduce how often users are logged out. It does not disable MFA or SAML SSO.

Did this answer your question?