How does Two-Factor Authentication (2FA) work?
We offer platform administrators the option to add an extra layer of security using Two-Factor Authentication (2FA); here’s how it works.
Upon request, it is possible to enable Two-Factor Authentication (2FA) and add an extra layer of security to your platform. Contact your Partnership Manager if you'd like this feature to be enabled. You can choose whether you'd like to make it optional or required for all your users.
Once the feature is enabled, all users can set up Two-Factor Authentication (2FA) to continue using the platform. The login procedure will then include an extra step where they canto link their authentication app (such as Google Authenticator or Authy - all authenticator apps using QR code / TOTP (time-based one-time password) should be supported).
- When an existing user logs in without having set up Two-Factor Authentication (2FA), they get a pop-up to set it up.
- New users can set up Two-Factor Authentication (2FA) after verifying their email address.
User Prompts when 2FA is enabled

Setting up 2FA

A new ‘Security’ tab will appear in each user’s account settings, where you can see the status, view backup codes, and disable Two-Factor Authentication (2FA) if you want to re-link your account.

Before enabling 2FA
You can consider to notify users in advance, for example one week, before making two-factor authentication (2FA) mandatory. This gives users time to prepare. For example, major platforms such as GitHub communicated this change ahead of time and provided clear guidance to users.
You can also consider taking a more personal approach to communication and offering additional support, especially if your platform is used by less technically experiences users. This may include step-by-step instructions, reminders, or direct assistance to help users successfully enable 2FA.
Do I need to set up 2FA for each Deedmob platform I'm using seperately?
No, this is not necessary. As you're using the same account for each platform, you can use the same 2FA code for each Deedmob platform you log in to.
My platform doesn't have 2FA enabled. Why does a user still have to enter a 2FA code?
This can happen when the user is also active on another platform that has made 2FA mandatory. Because users share one account across multiple platforms, the strictest security setting applies automatically.
The user sees this step not because your platform requires 2FA, but because another platform they have access to does.