> For the complete documentation index, see [llms.txt](https://docs-vnext.kiflo.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs-vnext.kiflo.com/account-settings/users-security/how-to-require-mfa-for-your-coworkers-and-partners.md).

# How to require MFA for your coworkers and partners?

Learn how to make multi-factor authentication mandatory for the people who access your workspace, and what your coworkers and partners will see the next time they sign in.

By default, MFA is optional: each person decides whether to secure their own account with an authenticator app. As an admin, you can make it mandatory instead, for your coworkers, for your partner users, or for both.

## Prerequisites

* You need an **Admin** or **Owner** role to change these settings.

## Require MFA

From the top-right menu, open **Account Settings**, then click **Security**. The **Multi-factor authentication** section is at the top of the page.

![](https://3041514930-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FKkJn82Qo5a0Y4fOsoQzo%2Fuploads%2Fgit-blob-910fb41b175a016cd3f6ed3d600e00925fb46161%2F6a7c5c483ece2a409e84504a.png?alt=media)

Turn on the group you want to cover:

* **My coworkers**: *Require MFA for my coworkers*, meaning everyone on your own team who signs in to this workspace.
* **Partner users**: *Require MFA for partner users*, meaning the people from your partner companies who sign in to your partner portal.

The two toggles are independent, so you can require MFA for your team without changing anything for your partners.

Click **Save**. Because turning a requirement on affects everyone in that group, Kiflo asks you to confirm with the **Enforce multi-factor authentication** dialog before saving.

![](https://3041514930-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FKkJn82Qo5a0Y4fOsoQzo%2Fuploads%2Fgit-blob-c992ac6a06cca7e4164d9ea0a877f8920fabd973%2F6a7c5c69ec01003aa68b9f19.png?alt=media)

## What the affected users see

There is no grace period, and nobody is signed out when you save. The requirement applies the next time each person reaches the workspace:

* People who already use an authenticator app notice nothing new. They keep entering their 6-digit code at sign-in, as before.
* People without MFA are stopped by a **Set up multi-factor authentication** screen that cannot be dismissed. Your coworkers are told that your organization requires MFA to continue, and partner users are told that your company requires it to keep accessing their partner portal. They scan the QR code, enter a code from their authenticator app, and get access straight away.

Users who are already signed in are not interrupted immediately. They are asked to set MFA up within a few minutes, the next time their session is renewed.

## MFA and single sign-on cannot both be enforced

With SSO, authentication is delegated to your identity provider, so Kiflo never asks those users for a code of its own. Any MFA you need there is configured in your identity provider.

Because of this, the two settings are mutually exclusive per group:

* If SSO is already **enforced** for a group, its MFA toggle is replaced by a note explaining that MFA cannot be required for those users.
* The reverse also applies. Once MFA is required for a group, the **Enforce** option of the matching SSO dropdown explains that single sign-on cannot be enforced for them.

Setting SSO to **Enable** rather than **Enforce** does not conflict with MFA. Those users can still sign in with a password, and when they do, they are asked for their MFA code.

## Your users cannot turn MFA off afterwards

MFA in Kiflo belongs to the person, not to the workspace: one authenticator app covers every workspace they can access. So while any of their workspaces requires MFA, the **Disable** button on their **User Preferences → Security** page stays greyed out, with the tooltip *One or more of your workspaces requires MFA*. It becomes available again if you turn the requirement off.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs-vnext.kiflo.com/account-settings/users-security/how-to-require-mfa-for-your-coworkers-and-partners.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
