Requiring Multi-Factor Authentication
Admins can require multi-factor authentication (MFA) for their whole company, or just for privileged roles. When MFA is required, users must confirm a one-time code from an authenticator app after their password, and anyone who has not set that up yet is walked through it before they can reach the app.
This guide is for admins. Individual users set up their own authenticator app from Profile & Settings.
Where to find it
- Click your profile at the bottom of the sidebar and choose Admin Settings.
- Open Company Settings (
/admin/settings/company). - Go to the Privacy & Security tab, under Authentication.
A banner at the top of the tab always shows the current state: MFA not active, MFA enforced for admin and HR roles only, or MFA enforced on every login.
The two settings
You have two mutually exclusive choices, plus the option to leave MFA off:
| Setting | Who must use MFA |
|---|---|
| Require MFA for all employees | Every user, on every sign-in |
| Require MFA for Admin / HR roles only | Super Admin, HR Admin, and IT Admin |
| (both off) | No one is forced; users may still opt in themselves |
"Admin and HR roles" means the privileged roles that can manage company settings: Super Admin, HR Admin, and IT Admin.
Turning one on turns the other off, so you are always in exactly one mode.
What happens at sign-in
When MFA is required for a user, their sign-in gains one step:
- They enter their email and password.
- If they already have an authenticator app set up, they enter the current 6-digit code to finish signing in.
- If they have not set one up yet, they are taken to a short enrollment screen. They scan a QR code with an authenticator app, enter a code to confirm, and save their backup codes. They cannot reach the app until this is done.
MFA here means a time-based code from an authenticator app such as Google Authenticator, Microsoft Authenticator, or Authy.
Users who are already signed in keep their current session. The requirement applies the next time they sign in.
Protect yourself from a lock-out
Set up your own authenticator app before you require MFA for admins. As a safeguard, Sparko will not let an admin who is out of compliance change this policy, so an admin without MFA cannot turn the requirement on and then get stuck behind it.
Every user gets backup codes during enrollment. Remind your team to store them somewhere safe in case they lose their phone.
Saving
The Save changes button at the bottom of the page only sends the fields you actually changed. The unsaved-changes dot turns amber until you save.
Related guides
- Admin Settings Overview: every admin surface at a glance
- First Login Guide: the MFA setup steps users follow
- Signing In With a Passkey: a phishing-resistant alternative