How to Configure Multi-Factor Authentication (MFA) Settings
This article explains how to enable and configure Multi-Factor Authentication (MFA) for your incubator. After reading it, you'll be able to set up authentication methods, define enforcement policies, and manage MFA for your users.
Introduction to MFA Settings
Multi-Factor Authentication (MFA) adds an extra layer of security to user accounts in your incubator by requiring users to verify their identity with a second method beyond their password. As an admin, you can choose which authentication methods are available, decide whether MFA is optional or mandatory, and define a grace period for users to complete their setup.
If you don't see this feature in your environment, contact your CSM to confirm your current plan.
This feature is available to Accelerator/Incubator admins only.
Where to Find MFA Settings
Navigate to the left sidebar menu → General Settings → left sidebar → MFA Settings.
Step-by-Step
1. Enable MFA for Your Incubator
On the MFA Settings page, toggle Enable Multi-Factor Authentication to turn the feature on for your incubator. Once enabled, users will be able to — or required to — set up an additional verification method depending on the policy you configure.
2. Select the Available Authentication Methods
Choose which MFA methods users can use. At least one method must be enabled. The available options are:
- Email — Users receive a one-time verification code via email.
- SMS — Users receive a one-time verification code via SMS. Standard message rates may apply.
- Authenticator App — Users generate time-based one-time codes using apps such as Google Authenticator or Authy.
Toggle on one or more methods according to your incubator's security requirements.

3. Set the Enforcement Policy
Define how MFA is applied to your users by selecting one of the following enforcement options:
- Optional — Users may set up MFA, but it is not required.
- Mandatory — All users must set up MFA before accessing the platform.
- Role-Based — MFA is enforced based on user roles (see Step 4 below).
4. Configure Role-Based Rules (if applicable)
If you selected Role-Based in the previous step, toggle on Role-Based Rules to reveal the configuration options. You'll then choose how roles are targeted:
- Require selected roles — Only the roles you select are required to set up and use MFA.
- Exempt selected roles — All roles except the ones you select are required to set up and use MFA.
Roles that are not required to set up MFA can still choose to enable it (User Security) — the difference is whether setup is mandatory or optional for them.
After choosing your rule type, open the roles dropdown and select the relevant user roles.

5. Define the Grace Period
Set the number of days users have to complete their MFA setup before access is restricted. The configurable range is 0 to 30 days.
- For existing users, the grace period starts on their first login after MFA is enabled.
- For new users, the grace period starts from the moment they sign up (their first login).
For example, if set to 10 days, users will have 10 days from their first login attempt to complete MFA setup.
6. Save Your Settings
Once all configurations are complete, click Save to apply your MFA settings to the incubator.
About Backup Codes
Backup codes are automatically enabled for all users as a recovery mechanism — no additional configuration is needed. During MFA setup, each user receives 8–10 one-time-use codes they can use to access their account if their primary MFA method is unavailable. Each code can only be used once.
Resetting a User's MFA as an Admin
If a user is locked out or needs their MFA reset, you can do this from the User Management page:
- Navigate to User Management.
- Locate the user and click the gear icon next to their name.
- Click on Reset Multi-Factor button.

Users can also reset or change their own MFA method independently by going to their User Security tab in their personal account settings.

Best Practices
- Enable at least two authentication methods so users have a fallback option if one is unavailable.
- Use the Mandatory policy for higher-security programs and Role-Based when only specific roles handle sensitive data.
- Set a grace period of at least 5–7 days to give users enough time to set up MFA without disrupting access.
- If a user reports being locked out, check User Management first before escalating — the Reset Multi-Factor option resolves most access issues quickly.