2FA for All Employee Roles
You can make all Employee roles in your account 2FA-required by enabling the 2FA for All Employee Roles feature.
If a user logs in NetSuite using either SAML Single Sign-on (SSO), or OpenID Connect (OIDC), the SAML, or OIDC authentication requirement takes precedence, and the 2FA requirement is ignored.
When you enable the feature:
-
All users with one or more Employee roles must set up 2FA.
-
Two-Factor Authentication Roles page shows all Employee roles as 2FA-required, and the option to change the requirement is unavailable. You can still change the values in the Duration of Trusted Device column.
-
The Two-Factor Authentication Required field on the Role page is not editable, because all Employee roles are 2FA-required. The Duration of Trusted Device column remains editable.
To enable the 2FA for All Employee Roles feature:
-
Go to Setup > Company > Enable Features (Administrator) and click the Company subtab.
-
In the Access section, check the Require 2FA for All Employee Roles box.
-
Click Save.
You can disable the feature at any time. If you disable the feature, the requirements you previously set on the Two-Factor Authentication Roles page apply again.
Disabling this feature significantly reduces account security. If you choose to disable it, configure 2FA requirements for individual employee roles on the Two-Factor Authentication Roles page or on each role record.