Security
Last updated
The organization-level Security settings in Autify Genesis control the allowed login methods for the organization and enforce two-factor authentication across every member.

To change security settings, you need the organization Admin or Owner role.
Require every member of the organization to register an authenticator app to reduce the risk of account takeover.
Open Settings from the account menu in the lower-left corner, and click Organization > Security in the left sidebar.
On the Two-factor authentication enforcement card, turn on the Require two-factor authentication switch.
Enter the Grace period (days) in the dialog that appears (0 to 90 days). Setting it to 0 blocks members immediately.

Click Enable enforcement.
During the grace period, a banner prompts unenrolled members to enroll. After the grace period ends, members without two-factor authentication enrolled are blocked from the organization.
For the steps individual members take to enable two-factor authentication, see Personal settings.
Open the Security page.
Turn off the Require two-factor authentication switch.
Restrict the authentication providers allowed for the organization. When every method is enabled, there is no restriction.
Open the Security page.
On the Login method enforcement card, turn on the switches for the methods you want to allow.
Email & password
Sign in with credentials registered directly in Genesis.
Sign in with a Google account.
Single Sign-On (SSO)
Sign in through a registered SSO provider (OIDC / SAML). Configure providers in Single Sign-On.
When only one method is enabled, it cannot be turned off.
When at least one method is disabled, a warning banner appears. Members who cannot sign in with any of the enabled methods will be blocked from the organization. Before restricting methods, confirm that members can reliably sign in with an allowed method.
Last updated