Set up multi-factor authentication (MFA)
Require a second login factor across your organization, with a grace period and enrollment tracking.
Multi-factor authentication (MFA) adds a second step to sign-in, so a password alone isn't enough to get into Brevity. Admins can require MFA across the whole organization, give existing users a grace period to enroll, and see at a glance who's covered.
Overview
With MFA turned on, users confirm their identity with a second factor after their password. Brevity supports:
- Authenticator apps (TOTP) — a rotating 6-digit code from an app like Google Authenticator, Microsoft Authenticator, or 1Password.
- Passkeys and security keys — a device passkey or hardware security key, used as a second factor.
- One-time recovery codes — a set of backup codes to keep somewhere safe, for when a user doesn't have their usual factor on hand.
MFA is off until an admin turns it on for the organization, and enrollment is per user.
What admins can do
- Require MFA across the org so every user must set up a second factor.
- Set a grace period for existing users, giving them a window to enroll before it's enforced.
- Enroll new users at first login so they set up MFA when they join.
- See who's covered from a single view of enrollment status across the org.
Turning on MFA for your organization
MFA is enabled per organization. To get set up, talk to your Customer Success Manager to turn on MFA for your account; then, as an admin, require it and set your grace period.
Once required:
- Existing users are prompted to enroll and have until the end of the grace period to do so.
- New users are prompted to set up MFA at first login.
Enrolling as a user
When MFA is required for your org, Brevity walks you through enrollment at sign-in:
- Choose a second factor — an authenticator app or a passkey / security key.
- Follow the prompts to register it.
- Save your recovery codes somewhere safe. If you ever lose access to your second factor, a recovery code gets you back in. [SCREENSHOT-2]
If your organization uses SSO or SAML
If you sign in to Brevity through single sign-on (SSO/SAML), you keep authenticating through your own identity provider — MFA is handled there, and there's nothing to change in Brevity. Your identity provider's own MFA policy applies.
FAQ
Which second factors can we use?
Authenticator apps (TOTP), passkeys and security keys, and one-time recovery codes as a backup.
We're on SSO — do we need to turn this on?
No. SSO/SAML organizations authenticate through their identity provider, which handles MFA. There's nothing to configure in Brevity.
What happens to existing users when we require MFA?
They're prompted to enroll and have until the end of the grace period you set. New users enroll at first login.
What if a user loses their phone or security key?
They use one of their one-time recovery codes to sign in, then set up a new factor. Encourage users to store recovery codes safely when they enroll.
Can an admin see who has set up MFA?
Yes — enrollment status across the org is visible in a single view.
Need help? Reach out to your Customer Success Manager.