In This Article

Overview

Multi-Factor Authentication Enforcement

Why MFA Is Mandatory

How to obtain the authentication code

Things to consider regarding MFA


Overview

Multi-Factor Authentication (MFA) adds an extra layer of security by requiring users to provide multiple verification factors during login.


As of release 2.11.9-2 (24 August 2026), MFA is mandatory for all WiredUp users across all cloud and on-premise deployments that do not use Single Sign-On (SSO). Users are required to authenticate using a verification code sent to their registered email address when signing in. Existing users who did not previously have MFA enabled are automatically enrolled and are prompted to complete MFA during their next login.


Note: MFA settings cannot be disabled for non-SSO users. Clients using Single Sign-On (SSO) are exempt as SSO provides equivalent authentication controls

Multi-Factor Authentication Enforcement

As of release 2.11.9-2, MFA is automatically enforced for all non-SSO users.


Administrators can still view the Multi-Factor Authentication setting on user profiles, however:

  • The Multi-Factor Authentication checkbox remains visible.
  • The checkbox is always selected.
  • The checkbox is greyed out and cannot be edited.
  • MFA cannot be disabled for any non-SSO user, regardless of role permissions.
  • No client-level override is available.

Existing users who previously had MFA disabled are automatically enrolled and will be prompted to authenticate using the existing email verification process during their next login.


All new users created after the release date have MFA enforced automatically. No administrator action is required.


Why MFA Is Mandatory

MFA helps protect user accounts by requiring an additional verification step during login.


The information tooltip displayed next to the Multi-Factor Authentication setting provides the following explanation:


Multi-Factor Authentication
Multi-Factor Authentication is enabled to protect your account and ensure only authorised users can access the platform. This setting is mandatory for all users

How to obtain the authentication code

  • Users who were automatically enrolled as part of the MFA enforcement release will be prompted to complete MFA during their next login. The authentication process remains unchanged and continues to use email-based verification codes.
  • Users must enter this code to access the system.
  • This additional step significantly enhances security and reduces the risk of unauthorized access.
  • Users have the option to select the 'Remember me on this device' setting for one day, which allows them to receive and enter the MFA code only once per day upon login.



Things to consider regarding MFA


Verification Code Expiry:

A verification code is only valid for 5 minutes.

A timer will display the remaining time for the code's validity.

Users can request a new code by clicking on the "Send Again" button if the code expires before use.


Code Expiry Handling:

After 5 minutes and the code expires, the input field for the code will lock.

Additionally, the submit button associated with entering the code will disable to prevent submitting an expired code.


Session Expiry:

If the user's session expires during the MFA process, they will be automatically redirected to the login page.

This ensures that the authentication process remains secure and up to date.


Resending Verification Code:

Users can click the "Send Again" button to request a new verification code.

If the user requests a new code before the previous one expires, the same code will be resent.

However, if the user clicks "Send Again" after the code expiry, a new verification code will be generated and sent to the user.


These considerations ensure a secure and streamlined MFA experience for users, maintaining the integrity of authentication processes and enhancing system security.
Note: MFA is not applicable to clients who have Single Sign On enabled. For all SSO clients, this can be managed by the organization.