Multi-Factor Authentication

4 min read

Add an extra layer of security to your enterprise workspace by requiring members to verify their identity with a second factor after signing in.

Multi-factor authentication (MFA) adds an additional verification step after signing in. Enterprise workspace owners can require all members to use MFA before accessing shared projects.

How It Works

When MFA is enabled for an enterprise workspace, members sign in as usual, then verify their identity with a second method before they can access that workspace. This applies to everyone in the workspace, including owners and admins.

Available verification methods:

Method How it works
Email verification A one-time code sent to your email
Authenticator app A code from Google Authenticator, Authy, or similar apps
Passkey Touch ID, Face ID, or a hardware security key

Members can use any one of the allowed methods. You do not need to set up all of them.

Google sign-in does not replace MFA. Even if you sign in with Google, you still complete the second verification step if the workspace requires it.

Enabling MFA for Your Enterprise Workspace

To require MFA for all workspace members:

  1. Open Settings from the left sidebar
  2. Go to General
  3. Scroll to the Security section
  4. Turn on Require two-factor authentication
  5. Check at least one verification method (Email verification, Authenticator app, or Passkey)

You need the Manage settings permission to change these options.

Choosing Verification Methods

Select the methods your team can use. Members only need one of the allowed methods to verify.

Recommendations:

  • Keep Email verification enabled as a backup. Every member already has an email address, so this prevents lockouts if someone loses their phone or device.
  • Add Authenticator app for stronger security. App-based codes are more secure than email since they use a separate channel.
  • Enable Passkey if your team uses devices with Touch ID, Face ID, or hardware security keys. Passkeys provide the smoothest experience with fewer prompts.

Important: Do not enable only Passkey. If a member loses their device, they have no way to verify. The settings page prevents this, but keep at least one other method checked.

When Changes Take Effect

After you enable or change MFA settings, existing sessions update within about an hour. Members are not immediately signed out. They complete verification on their next workspace switch or when their session refreshes.

Setting Up Your Security Credentials

Manage your verification methods in Account settings:

  1. Click your avatar at the bottom left of the sidebar
  2. Select Account settings
  3. Go to the Security section

From here you can:

  • Set up an authenticator app by scanning a QR code with your preferred app
  • Add a passkey using your device’s biometric or security key
  • Change your password or link Google for sign-in convenience (these are not second factors)

If a workspace requires MFA and you have not set up a method yet, you are prompted to do so when you switch to that workspace. You do not need to visit Account settings first.

Switching to a Protected Workspace

When you switch to a workspace that requires MFA:

  1. A dialog appears: “{Workspace name} requires multi-factor authentication”
  2. Click Verify and switch
  3. Complete verification using one of the allowed methods
  4. The workspace loads after successful verification

If you have not enrolled a verification method yet, the prompt walks you through setup before verification.

Passkeys and Session Refresh

Members who sign in with a passkey have a smoother experience. Passkey verification satisfies the MFA requirement across session refreshes, so you are not prompted repeatedly.

Members who sign in with a password or Google may see verification prompts approximately once per hour while working in an MFA-protected workspace. If your team finds this disruptive, encourage members to set up passkey sign-in.

FAQ

What is the difference between 2FA and MFA?

They refer to the same feature. Two-factor authentication (2FA) and multi-factor authentication (MFA) both mean verifying your identity with a second method after your password. Sticklight uses both terms interchangeably.

Does Google sign-in count as MFA?

No. Signing in with Google is a convenience feature, not a second factor. If your workspace requires MFA, you still need to verify with email, an authenticator app, or a passkey after signing in with Google.

Can I require MFA for admins only?

No. The policy applies to all workspace members equally. There is no option to require MFA for specific roles.

Is SMS verification available?

No. Sticklight does not offer SMS-based verification. Use email, an authenticator app, or a passkey instead.

What happens if I lose my phone?

If you lose access to your authenticator app or passkey device, use email verification as a backup. This is why workspace owners should keep email verification enabled alongside other methods.

I enabled MFA but members can still access without verifying. Is it broken?

No. Changes take effect within about an hour. Existing sessions are not immediately invalidated. Members complete verification on their next session refresh or workspace switch.

Can I use MFA on my personal workspace?

MFA is an enterprise feature and therefore not available for personal workspaces unless they are part of an enterprise account.

Last updated: October 4, 2026

Was this article helpful?