
Security policies are rules that apply to everyone in a space. Today there is one: Require two-factor authentication. When it is on, every member needs a second factor before they can open the space. Members who already use 2FA notice nothing. Members who do not are sent to a setup page and come straight back once they are done.
Only Admins and the Owner can open the Policies page. For other roles the entry is greyed out in the sidebar with the note Admin only. Enforcing 2FA is part of the Pro plan.
For how a member sets up 2FA on their own account, see Authentication.
Click the gear icon at the bottom of the left rail to open Settings.
Under Security, click Policies. The page is titled Security policies.
The rule takes effect at once and the switch shows Enforced - every member needs two-factor authentication. The change is recorded in the audit log.
Tell your team before you switch it on. Everyone without 2FA is interrupted with the setup page the next time they open the space.
Members without a second factor see the page Two-factor authentication required when they open the space, with the note that the space asks every member for a second factor.
They click Set up two-factor authentication, scan the QR code, verify, and save their backup codes. Then they go straight back to the space.
Open sessions are checked on every page, so the rule applies right away, not only at the next sign-in.
The Profile and Authentication pages stay reachable without 2FA, so a member can always complete the setup.
You can see who has 2FA in the 2FA column of the member list under Settings → Team.