Skip to content

Multi-Factor Authentication (MFA)

Enjade supports TOTP-based multi-factor authentication for enhanced account security.

Enabling MFA

For Your Account

  1. Click your profile icon in the top right
  2. Select Security Settings
  3. Click Enable MFA
  4. Scan the QR code with your authenticator app (Google Authenticator, Authy, 1Password, etc.)
  5. Enter the 6-digit code to verify setup
  6. Save the backup codes in a secure location

For Your Organization (Admin)

Tenant administrators can enforce MFA for all users:

  1. Navigate to Admin Panel > Security
  2. Toggle Require MFA for all users
  3. Set a grace period for users to enable MFA (e.g., 7 days)

Logging In with MFA

  1. Enter your email and password as usual
  2. When prompted, enter the 6-digit code from your authenticator app
  3. Optionally check Remember this device (30-day trust period)

Backup Codes

When you enable MFA, you receive one-time backup codes:

  • Each code can only be used once
  • Store them securely (password manager, printed copy in safe)
  • Use a backup code if you lose access to your authenticator app
  • Generate new backup codes from Security Settings if needed

Disabling MFA

  1. Go to Security Settings
  2. Click Disable MFA
  3. Enter your current TOTP code to confirm
  4. MFA is removed from your account

Warning

If your organization requires MFA, you cannot disable it for your individual account.

Account Lockout

Enjade uses progressive account lockout for failed login attempts:

  • After 5 failed attempts: 5-minute lockout
  • After 10 failed attempts: 30-minute lockout
  • After 15 failed attempts: Account locked (admin unlock required)