Kasimir Docs DEEN To the app →

Two-factor requirement

Require two-factor for the whole company, member status and resets.

Owners and admins can require all members to sign in with a second factor under Administration → Security.

Turn on the requirement

  1. Open Administration → Security, section “Two-factor authentication”.

  2. Turn on Require for all members.

  3. Choose a grace period (none to several days). Until then, members without a second factor only see a reminder; afterwards they are guided to set one up when signing in.

  4. Decide whether Sign-in via Google/Microsoft counts as fulfilled — then the two-factor policy of your Microsoft or Google account applies.

Passkeys always satisfy the requirement. You can only turn on or tighten the requirement while you are strongly signed in yourself (code, passkey or — if allowed — Google/Microsoft). That way you cannot lock yourself out.

Member status

Under “Members and their status” you see for each person whether an authenticator, a passkey, both or none is set up.

Reset two-factor

If someone lost their phone, click Reset 2FA for that person. All their authenticator entries and passkeys are deleted; they set them up again at their next sign-in. The action is recorded in the audit log.

Every policy change, every setup, removal and reset, and sign-ins from new devices appear in your company’s audit log.