Tutorial

Enforce 2FA across your workspace

Require 2FA across your whole workspace — on every plan, including Free. Authenticator app, recovery codes, and a guided setup for every member.

Last updated:

With most project tools, mandatory two-factor authentication is an enterprise feature — available only on the most expensive tier, sometimes only after a call with sales. In Zuuna it belongs to every plan, including the free one. You switch the mandate on once, and from then on nobody works in your workspace without an authenticator app — anyone without 2FA is walked through setup on their very next click.

What you need

  • A Zuuna workspace — any plan works, including Private Free (see pricing).
  • The security.manage permission. It belongs to the Superadmin role by default — the workspace owner is a Superadmin — and is deliberately excluded from the admin preset. It can additionally be granted through a custom role; security policy is not something every admin changes.
  • An authenticator app on your phone. Any TOTP app works — Google Authenticator, Microsoft Authenticator, Authy, 1Password and all the rest.

1. Turn on 2FA for yourself first

Before you make it mandatory for everyone, set it up on your own account: start the setup in your account settings, confirm with your password, and add the account to your authenticator app. From now on Zuuna asks for the six-digit code from the app at every login.

2. Store your recovery codes

During setup you get ten one-time codes for the day the phone goes missing. Put them in your password manager — now, not later: the codes are stored only as hashes and can never be shown again, not even by an admin.

3. Enable the workspace mandate

In Administration under “Security & Access” you switch on the 2FA mandate for the whole workspace. The policy takes effect within seconds — no restart, no email campaign, no waiting.

4. What your members see afterwards

Nobody is thrown out of a running session. Anyone already using 2FA notices nothing — the mandate enforces enrollment, not a different method. Anyone without it is walked through setup on their very next click, on every device, and then carries on working. People you invite later go through the setup right at their first login.

5. When someone loses their phone

That is what the recovery codes are for: the person signs in with one of their ten one-time codes and then sets 2FA up again on the new device. Each code works exactly once. As an admin you never see the codes — they are stored only as hashes. Which is exactly why they belong in a password manager from day one.

6. Check status and the audit log

The user directory shows you, for every member, whether 2FA is on — next to role, teams and last sign-in. And the security audit log records who changed the policy, when, and from which IP address. Said honestly: it covers the last 100 events at workspace level, with no export and no filtering.

Troubleshooting

  • You cannot find the switch. You lack security.manage — by default the permission sits only with the workspace owner.
  • A member sees no setup. The guided setup starts on the next navigation — one click or a reload is enough. The policy itself takes effect within seconds.
  • Phone and codes are both gone. That is the case the ten codes exist to prevent — they cannot be recovered. Treat them like a password: password manager, not desk drawer.
  • You lift the mandate again. Zuuna automatically switches 2FA off only for people who enrolled solely because of the mandate. Voluntary enrollments stay — and so does everyone still covered by another workspace's mandate.

Next steps

FAQ

Does the 2FA mandate cost extra?

No. Enforced two-factor authentication is included on every plan, including Private Free — while many competitors only offer it on an enterprise tier.

What happens to members who are logged in right now?

Nobody is thrown out of their session. Anyone without 2FA is walked through setup on their next click and then carries on working normally.

What if someone loses their recovery codes?

The ten one-time codes are stored only as hashes and can never be shown again afterwards — not even by admins. So store them in a password manager right at setup.

Can I see who has 2FA enabled?

Yes. The user directory shows, for every member, whether two-factor authentication is on. What you never see are the secrets behind it — the app key is encrypted, the codes are hashed.

Does the 2FA mandate replace single sign-on?

No — the two solve different problems. 2FA secures the password login and is on every plan; SSO via SAML 2.0 or OpenID Connect moves login to your identity provider and belongs to Business Pro. You can combine both.

Rebuild this step in your own workspace.

The guide takes a few minutes — it sticks when it is your own board underneath. 14 days of full access, no credit card.