How to Set Up Multi-Factor Authentication (MFA)
How to Set Up MFA
Multi-factor authentication adds an extra layer of security to your account — when you sign in with email and password.
When MFA is not needed
| Your org uses… | What you do |
|---|---|
| SSO (Single Sign-On — Microsoft Entra ID, Google Workspace, etc.) | Sign in through your corporate identity provider. You do not set up MFA inside Intelligent Roster — your IT team's SSO/MFA policy applies. See Logging In with SSO. |
| Email + password, MFA not required by policy | MFA is optional unless your admin enforces it for your role. |
| Email + password, MFA required | You'll be prompted to enable MFA after login (may include a grace period). |
If Security Settings shows "Single Sign-On (SSO) Active", the MFA setup options are hidden — that is expected.
Set up MFA (email + password users only)
- Go to Profile → Security Settings
- Click Enable MFA
- Scan the QR code with your authenticator app:
- Google Authenticator
- Microsoft Authenticator
- Authy
- Any TOTP-compatible app
- Enter the 6-digit code from your app to verify
- Save your recovery codes somewhere safe
When logging in with MFA:
- Enter your email and password as usual
- You'll be prompted for your 6-digit authenticator code
- Enter the current code from your app
- You're in!