Sign-in methods and two-factor policy
Choose how your team signs in, decide who must use two-factor authentication, and reset it for someone who is locked out.
Not every agency runs on Google Workspace. Everyone you add can sign in with Google or with a one-time link sent to their email, so nobody needs a Google account. Settings lets you switch either method off and decide who must use two-factor authentication.
Two-factor policy
- Optional: anyone can turn it on for themselves. Nobody is required to.
- Required for admins: workspace admins must set it up before they can do anything else. Everyone else is optional.
- Required for everyone: every person is held at setup on their next sign-in until it is on.
Steps
- Open Settings and choose the Security tab.
- Pick the policy, and switch sign-in methods on or off. At least one method must stay on.
- Click Save changes.
Helping someone who is locked out
If a person has lost their phone and their recovery codes, find them in the People list on the Security tab and click Reset. Their old authenticator app and codes stop working immediately and they set it up again at their next sign-in. Every reset is recorded in the audit log.
Start with Required for admins. Admin accounts can change billing, permissions and data for the whole workspace, so they benefit most from the extra step.
Questions
We do not use Google Workspace. Can our team still sign in?
Yes. Everyone can sign in with a one-time link sent to their invited email address, and you can switch Google off entirely under Settings, then Security.
Can I turn both sign-in methods off?
No. At least one method must stay on, and the settings page refuses to save otherwise.
When does a new policy apply?
From each person's next sign-in. Someone the policy covers who has not set up two-factor authentication is held at setup until it is on.