Blog

Require 2FA for every user on your Signater account

Passwords are only one layer of account security. Signater admins can require two-factor authentication for every user, including new users who join the account later.

Require 2FA for every user on your Signater account

A compromised password can be enough to get someone into an account.

And a Signater account can contain contracts, customer documents, templates and envelopes waiting for signatures. When access depends on a password alone, one compromised credential can put a lot at risk.

Two-factor authentication (2FA) adds another authentication factor after the password. With Signater, account admins can go one step further and require 2FA for every user on the account.

Instead of relying on each employee to enable it themselves, the account can enforce the same sign-in requirement for everyone.

What is two-factor authentication?

Two-factor authentication requires two authentication factors from different categories before a user can sign in.

On Signater, the first factor is the user's password. The second factor is a temporary six-digit code generated by an authenticator app on the user's phone, such as Google Authenticator or Authy.

The code changes every 30 seconds and uses TOTP (time-based one-time password). Because the code is generated by the authenticator app, the Signater 2FA flow does not depend on SMS delivery.

That means a person who obtains another user's Signater password still needs access to the configured authenticator to complete the login.

Why require 2FA for everyone?

Security policies are harder to enforce when they depend entirely on individual users.

Imagine a team of ten people. Nine have enabled 2FA, but one person still signs in with a password alone. That one account can become the weak point if its credentials are compromised.

When an admin requires 2FA, the policy applies consistently across the account. It covers existing users who haven't enabled it yet and applies to users who join the account later.

This is especially useful for teams that handle sensitive contracts, customer information or documents that require tighter access controls.

How to require 2FA for all users

Account admins can enable the requirement from:

Settings → Account → General → Features

  1. Turn on Require 2FA for all users.
  2. Click Save.

If the admin hasn't configured 2FA for their own account yet, Signater requires them to complete their own setup first.

This prevents an administrator from enforcing a two-factor policy while their own account is still protected by a password alone.

What happens to users who don't have 2FA yet?

The next time a user signs in, Signater shows Two-factor authentication required.

They must complete the 2FA setup before they can continue using the account. They can either configure their authenticator at that point or sign out.

The requirement applies to every user on the account, regardless of role. That includes admins and account owners.

Users who already have 2FA enabled don't need to change anything. Their sign-in process continues as normal.

How users set up 2FA

Setting up 2FA takes only a few steps:

  1. Install an authenticator app on a phone, such as Google Authenticator or Authy.
  2. Scan the QR code displayed by Signater.
  3. Enter the six-digit code generated by the authenticator.
  4. Click Verify and activate.
  5. Save the recovery codes somewhere secure.

After setup, the user enters a code from the authenticator app after their password whenever they sign in.

The same requirement applies when a user signs in with Google. After Google authenticates the account, Signater still asks for the configured second factor.

What happens if a user loses their phone?

That's what recovery codes are for.

When 2FA is enabled, Signater provides recovery codes that can be used if the user loses access to their authenticator app. On the sign-in screen, the user selects Use recovery code instead and enters one of the saved codes.

After signing in, they can configure a new authenticator and generate new recovery codes from Settings → Profile → Security.

Recovery codes should be stored somewhere secure and separate from the phone, such as a password manager.

How to roll out required 2FA to your team

Enforcing 2FA is straightforward, but a little preparation can prevent unnecessary disruption.

  1. Let your team know ahead of time. Tell users that the sign-in requirement is changing.
  2. Ask them to install an authenticator app. They can have it ready before the policy takes effect.
  3. Remind everyone to save their recovery codes.
  4. Enable the requirement at a convenient time. Avoid rolling it out in the middle of an urgent signing workflow.

A few minutes of preparation can save your team from discovering the new requirement when they are trying to send or sign an important contract.

Required 2FA only applies to your account users

The account-wide 2FA requirement protects access to your Signater account.

It does not apply to people who receive your envelopes. Your customers, vendors, partners and other external signers do not need to create a Signater account or install an authenticator app just because your account requires 2FA.

Verification for external signers is configured separately for each envelope. Depending on your workflow, you can use factors such as email verification, SMS verification, a selfie or facial biometrics.

See all available identity validation options.

Availability

Requiring 2FA for every user is available on Signater's Business and Enterprise plans. Individual 2FA is available on every plan, including Free.

Signater also provides additional security features for protecting your account and documents.

Want to try Signater? Create a free account and send up to three envelopes per month on the Free plan, with no credit card required.

People in front of a laptop reviewing its screen

Get started

Your Contracts Signed in Minutes

Create your free account: 3 envelopes a month, forever, no credit card. Streamline document signing and accelerate your processes today.