Set up 2FA and security for staff

You can require all staff members to use two-factor authentication (2FA) to access Managello. Note that 2FA applies to staff only — clients sign in through single-use magic links and never use 2FA.

How to enable

  1. Go to Settings → Security → Require 2FA for all staff.
  2. Toggle it on.
  3. Existing staff are prompted to enrol on their next login.

Supported method

Managello uses authenticator-app (TOTP) codes — Google Authenticator, 1Password, Authy, Microsoft Authenticator, and any other standard authenticator all work. There is no SMS option (SMS is widely considered the weakest form of 2FA).

Enrolling (for staff)

On next login, each staff member scans a QR code with their authenticator app and confirms one code to finish. It takes about 30 seconds. They're also shown one-time recovery codes — tell them to save these somewhere safe.

Recovering access

If someone loses their phone, they can sign in with one of the recovery codes they saved at enrolment. If those are gone too, an admin can reset that member's 2FA from Settings → Team, after which they re-enrol on next login.

Was this article helpful?