Two-factor authentication and login activity
Turn on two-factor authentication with an authenticator app, add an SMS backup, manage trusted devices, and review the sign-ins to your account and team.
Two-factor authentication asks for a 6-digit code from your phone after you sign in, so a stolen password alone is not enough to enter your account. Everything in this article is on one tab: Settings → Login & security (/settings/security). The tab has four sections: Password, Two-factor authentication, Trusted devices and Login activity.
Turn on two-factor authentication
Make sure you have a password
Two-factor codes protect a password sign-in. An account that signs in only with an emailed code sees "Set a password to enable two-factor authentication." with a Go to password settings button; set a password first (see Sign in and recover access), then come back.
Start the setup
In the Two-factor authentication section click Enable two-factor authentication. If the app asks Confirm it's you, type your password and click Confirm, or use Confirm with Google; you continue where you left off.
Scan the QR code
The Set up authenticator app window shows a QR code. Scan it with an authenticator app (for example Google Authenticator or 1Password). If you cannot scan, open Can't scan? Enter this key manually and type the key into the app.
Enter the code
Type the 6-digit code from the app in Verification code and click Verify & enable. You see Two-factor authentication is now enabled and the section lists Authenticator app with an Active tag.
Add an SMS backup (recommended)
Click Add SMS backup, enter your Phone number in international format (for example
+48123456789), click Send SMS code and confirm with the code from the text message. "A
backup phone number lets you sign in by SMS code if you lose access to your authenticator app."
Signing in with two-factor authentication
After the password, the Two-Factor Authentication screen asks for the 6-digit code from your authenticator app. With an SMS backup you can click Can't use your authenticator app? Get an SMS code instead. The checkbox Don't ask again on this device for 30 days is ticked by default; leave it on for your own computer and untick it on a shared one.
An account with two-factor authentication cannot sign in with an emailed login code; the login page says "This account is protected by two-factor authentication. Sign in with your password instead."
Trusted devices
| Column | Meaning |
|---|---|
| Device | The browser and system that were trusted |
| Added | When you ticked Don't ask again on this device |
| Last used | The last sign-in that skipped the code |
| Expires | When the device will be asked for a code again |
Click Revoke next to a device and confirm Revoke trust for this device? to require the full check on its next sign-in. Do this for a lost or sold device.
Login activity
The Login activity table lists recent sign-ins with Date, Email, Method (Password, Google, Code, Trusted device and others), Status, IP Address and Device. Besides Success and Failed sign-ins it also records Logout, 2FA enabled, 2FA removed, Device trusted and Device trust revoked. Load More shows older entries.
The workspace Owner and Admins get a switch above the table: All shows the sign-ins of every team member, My Logins only their own. Other roles see only their own sign-ins and no switch.
Remove a verification method
Click Remove next to Authenticator app or SMS backup and confirm Remove this verification method?. For your security the app may sign you out afterwards: "The verification method was removed. For your security, you've been signed out - please log in again."
Good to know
Two-factor authentication belongs to your account, not to a workspace: it protects every workspace you sign in to, and each team member turns it on for their own account. If you see an entry in Login activity that you do not recognize, change your password and revoke the trusted devices you do not use.
Was this article helpful?

