2FA for All Employee Roles

You can make all Employee roles in your account 2FA-required by enabling the 2FA for All Employee Roles feature.

Note:

If a user logs in NetSuite using either SAML Single Sign-on (SSO), or OpenID Connect (OIDC), the SAML, or OIDC authentication requirement takes precedence, and the 2FA requirement is ignored.

When you enable the feature:

To enable the 2FA for All Employee Roles feature:

  1. Go to Setup > Company > Enable Features (Administrator) and click the Company subtab.

  2. In the Access section, check the Require 2FA for All Employee Roles box.

  3. Click Save.

You can disable the feature at any time. If you disable the feature, the requirements you previously set on the Two-Factor Authentication Roles page apply again.

Warning:

Disabling this feature significantly reduces account security. If you choose to disable it, configure 2FA requirements for individual employee roles on the Two-Factor Authentication Roles page or on each role record.

Related Topics

General Notices