Recent searches

in

Enforce multi-factor authentication

Last modified: September 10th, 2026

Enforced multi-factor authentication is available on our Team or Enterprise Plan.

For questions about this feature, contact our support team.

Permissions required

Members of the Owners and Partner Default Permission Groups can enforce multi-factor authentication for an Organization. Custom Permission Groups cannot be granted this permission.

Requiring your Team Members to use multi-factor authentication on CloudCannon can add an extra layer of security to your Organization.

MFA enforcement applies to everyone in your Organization, including you. If you do not have multi-factor authentication enabled on your own account when the date passes, you will lose access to the Organization until you enable it.

To enforce multi-factor authentication for your CloudCannon Organization:

  1. Navigate to the Multi-Factor Authentication page under Org Settings.
  2. Check the Require multi-factor authentication (MFA) for everyone in your organization checkbox.
  3. In the Require MFA after field, enter the date after which CloudCannon will require multi-factor authentication to view your Organization, in YYYY-MM-DD format.
  4. Click the Update Organization button.

CloudCannon will update your Organization.

A screenshot of the Multi-Factor Authentication page shows a checkbox and date field for enforcing MFA.

After the specified date, CloudCannon will require Team Members in your Organization to have multi-factor authentication enabled to view your Organization and Sites. You can update the date and disable enforced multi-factor authentication at any time.

As the date approaches, Team Members who have not yet enabled multi-factor authentication will see a warning banner, informing them that your Organization will soon require multi-factor authentication.

A screenshot of the MFA required warning banner shows that you must enable MFA on your account by a given date to retain access to this Organization.

If a Team Member has not enabled multi-factor authentication before that date, they can log in to CloudCannon but cannot access your Organization.

A screenshot of the Organizations page shows that access to an Organization is prevented because MFA is required.
A screenshot of the MFA Required page shows that you cannot access an Organization until you enable MFA for your account.

A Team Member can restore access to your Organization by enabling multi-factor authentication on their CloudCannon account.

You can view which Team Members have multi-factor authentication enabled on the Team page under Org Settings.

A screenshot of the Team page shows which Team Members have enabled MFA.

Alternatively, you can export an Access Review and use the MFA Enabled column to review which Team Members have multi-factor authentication turned on. For more information, please read our documentation on what an Access Review is.

Related Resources

Open in a new tab