{"id":2554,"date":"2025-07-02T12:43:37","date_gmt":"2025-07-02T12:43:37","guid":{"rendered":"https:\/\/zecurit.com\/help\/docs\/asset-manager\/settings\/security-compliance\/two-factor-authentication\/"},"modified":"2025-07-04T05:47:08","modified_gmt":"2025-07-04T05:47:08","slug":"two-factor-authentication","status":"publish","type":"docs","link":"https:\/\/zecurit.com\/help\/asset-management\/settings\/security-compliance\/two-factor-authentication\/","title":{"rendered":"Two-Factor Authentication"},"content":{"rendered":"\n<p>Two-Factor Authentication (2FA) adds an extra layer of security to your Zecurit account by requiring a one-time passcode (OTP) in addition to your regular password. This helps protect your organization from unauthorized access, even if login credentials are compromised.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>Note: Only the Super Admin can enable or disable 2FA for your organization.<\/p>\n<\/blockquote>\n\n\n\n<h3 class=\"wp-block-heading\">What Happens When 2FA is Enabled?<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Mandatory for All Users<\/strong>: Once 2FA is turned on, it becomes <strong>required for every user<\/strong> on the platform.<\/li>\n\n\n\n<li><strong>Setup on Next Login<\/strong>: Users will be prompted to <strong>complete their 2FA setup<\/strong> during their next login session.<\/li>\n\n\n\n<li><strong>OTP Delivery<\/strong>: A <strong>One-Time Passcode<\/strong> is sent to the user\u2019s <strong>registered email address<\/strong>.<\/li>\n\n\n\n<li><strong>OTP Validity<\/strong>: The passcode is <strong>valid for 15 minutes<\/strong> from the time it is generated.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Login Flow with 2FA Enabled<\/h3>\n\n\n\n<ol class=\"wp-block-list\">\n<li>User enters username and password as usual.<\/li>\n\n\n\n<li>Zecurit sends an <strong>OTP to the registered email<\/strong>.<\/li>\n\n\n\n<li>User enters the OTP to complete login.<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">Super Admin Control<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>Action<\/th><th>Description<\/th><\/tr><\/thead><tbody><tr><td>Enable\/Disable 2FA<\/td><td>Only the <strong>Super Admin<\/strong> can toggle this setting under <strong>Settings \u2192 Security<\/strong> <strong>\u2192 2F Authentication<\/strong><\/td><\/tr><tr><td>Global Enforcement<\/td><td>Once enabled, applies to <strong>all users<\/strong><\/td><\/tr><tr><td>No User Opt-Out<\/td><td>Individual users cannot bypass or disable 2FA<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">Account Lockout Protection<\/h3>\n\n\n\n<p>To safeguard against <strong>brute-force attacks<\/strong>, we&#8217;ve implemented an account lockout policy.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>5 incorrect OTP attempts<\/strong> \u2192 The user\u2019s account is <strong>temporarily locked<\/strong>.<\/li>\n\n\n\n<li>Both <strong>Super Admin<\/strong> and <strong>Administrators<\/strong> have the ability to <strong>unlock these accounts<\/strong>.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Troubleshooting<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Didn\u2019t Receive OTP?<\/strong>\n<ul class=\"wp-block-list\">\n<li>Check your spam or junk folder.<\/li>\n\n\n\n<li>Ensure your registered email is correct.<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>Locked Out?<\/strong>\n<ul class=\"wp-block-list\">\n<li>Contact your Super Admin or IT administrator for help unlocking your account.<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>Email Delivery Delays?<\/strong>\n<ul class=\"wp-block-list\">\n<li>Delays may occur due to mail server issues. Wait briefly and retry.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<p><\/p>\n","protected":false},"featured_media":0,"parent":2553,"menu_order":0,"comment_status":"open","ping_status":"closed","template":"","doc_tag":[],"class_list":["post-2554","docs","type-docs","status-publish","hentry"],"comment_count":0,"_links":{"self":[{"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/docs\/2554","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/docs"}],"about":[{"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/types\/docs"}],"replies":[{"embeddable":true,"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/comments?post=2554"}],"version-history":[{"count":2,"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/docs\/2554\/revisions"}],"predecessor-version":[{"id":2612,"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/docs\/2554\/revisions\/2612"}],"up":[{"embeddable":true,"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/docs\/2553"}],"wp:attachment":[{"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/media?parent=2554"}],"wp:term":[{"taxonomy":"doc_tag","embeddable":true,"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/doc_tag?post=2554"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}