Introduction
Multi-factor authentication (MFA) adds a second step when members sign in to their NordPass Business account. You can require an Authenticator app (6-digit code), a security key (physical FIDO2 device, e.g., YubiKey), or both. Enforcing MFA helps protect your organization against phishing and unauthorized access. Members complete setup on their next sign-in (or immediately, if you choose to log them out). This MFA layer does not replace your identity provider’s MFA with SSO. If your users are already required to use MFA each time they use SSO, avoid adding another MFA layer on NordPass.
This guide will explain how to set up mandatory Multi-factor authentication (MFA) for your organization members via the NordPass Business admin panel.
Note: If your organization's MFA is already set up, encourage members to set it up using our guide.
Before you start
As an Admin, you can control MFA for several organization layers and configure different MFA method policies per role or member:
Two areas:
- Organization settings - used for the default MFA policy per role (Owners, Admins, Users).
- Member settings - Customer MFA for specific members (overrides organization settings).
MFA methods you can enforce:
- Authenticator app - Mobile app that shows a 6-digit code.
- Security key - Physical device member taps or inserts into a USB port when prompted.
- Both - Members must set up the security key first, then the Authenticator app as a secondary method.
- None - Members are not required to set up MFA, but may do so voluntarily. Disabling enforcement does not disable MFA methods; Admins must reset them, or members must disable them manually.
What members see when policy is enforced:
- Enforced methods are required to be set up on the next login, or right away if you log them out.
- MFA will be prompted after the business account password or SSO and before the Master Password.
- How often MFA is prompted together with the business account password or SSO can be configured in Account session controls.
- A security key is considered a more secure MFA layer. It can be set up manually by the user, even though the Authenticator app is the only enforced option.
Here's what to do
How to enforce MFA for your organization by role
- Log in to the NordPass Business admin panel as the organization Owner or Admin.
- Select the "Authentication" button located on the left side, and click on the "Multi-factor authentication" button.
- Click on the "Edit" button located next to "Enforce multi-factor authentication".
- For each role (Owners, Admins, Users), choose the required method:
- None (Not enforced).
- Authenticator app only.
- Security key only.
- Both ( Security key and Authenticator app).
- Afterwards, click on the "Save" button.
- If you are turning enforcement on or making it stricter, choose when it applies:
- On next log in - members keep current sessions until they sign in again.
- Immediately - affected members (including you, if applicable) are logged out and must sign in and complete the MFA setup.
- Confirm "Enforce multi-factor authentication?" if prompted. The "Changes saved" message will appear when the policy is updated.
Note: Relaxing the policy does not delete methods members already configured. They can still use MFA voluntarily unless you remove their methods.
How to set custom MFA for individual members
- Log in to the NordPass Business admin panel as the organization Owner or Admin.
- Select the "Authentication" button located on the left side, and click on the "Multi-factor authentication" button.
- Next, select the "Member settings" option and click on the "Add Member".
- Afterward, enter the member's email address that already exists in your organization.
- Set up the Authenticator app and/or a security key for that member.
- Click on the "Add" button and select "Save".
Note: Custom settings overwrite organization settings for that member. You can remove custom settings later to restore the role to default. Follow our guide if you wish to reset MFA for your organization members.