Documentation
Configuring SSO and MFA policies
Enforce organization-wide identity requirements without disrupting active members.
Turning on enforcement
Organization → Security policy contains two switches: requiring single sign-on and requiring two-factor authentication for every member. Both apply immediately to new sign-ins; existing sessions are not interrupted.
Rolling out gradually
Most organizations enable two-factor authentication first, give members a short window to enroll a method from Settings → Two-factor authentication, and enable SSO enforcement once their identity provider integration is verified.
Recovery paths
Members can enroll multiple two-factor methods (an authenticator app and a backup SMS number, for example) so a single lost device doesn't lock them out. Admins can also view and revoke a member's methods if needed.