Examplary
  • Start for free
    All guides

    Examplary for organizations

    Requiring two-factor authentication

    Two-factor authentication asks for a six-digit code from an authenticator app on top of a password, so a leaked or guessed password isn't enough on its own to get into an account.

    Anyone can switch it on for themselves under Account → Security. As an administrator, you can go further and require it for everyone in your workspace.

    Available plans

    Requiring two-factor authentication across a workspace is available on the Examplary for organizations plan. Individual members can turn it on for their own account on any plan. If you're interested in upgrading, contact us via hi@examplary.ai.

    Who it applies to

    Two-factor authentication protects password sign-ins. That's the only place it makes sense, so several groups are deliberately left out:

    WhoAffected?Why
    Teachers and admins with a passwordYesThis is what the second factor protects
    Students using a magic code or linkNoThere's no password to protect
    Anyone signing in through Google, Entree Federatie or your own identity providerNoYour identity provider owns the policy — set it up there
    API keys and OAuth access tokensNoSeparate credentials, issued deliberately, revoked separately
    If you use single sign-on

    Requiring two-factor authentication does nothing for a workspace that already signs in through an identity provider — those members never enter an Examplary password. Configure the requirement in Google Workspace, Entree, Entra ID or wherever your accounts live. See Setting up single sign-on.

    Turning it on for your workspace

    Go to Account → Access & domains and switch on Require two-factor authentication.

    From then on, any member who signs in with a password and hasn't set up an authenticator app is stopped at a Set up two-factor authentication screen and can't use Examplary until they've enrolled. They don't need an invitation or a link, the screen appears on its own the next time they load the dashboard.

    Enrol yourself first

    Set up your own authenticator app under Account → Security before you switch the requirement on, and tell your colleagues it's coming. Nobody is locked out of their account by this — they just can't get past the enrolment screen — but people tend to hit it mid-task, and it's a better experience when they're expecting it.

    Switching the setting on can take up to 15 minutes to reach everyone in the workspace. Members who are already signed in when you switch it on might be able to carry on using Examplary until they sign out, at which point they'll be stopped at the enrolment screen.

    What your members will see

    The enrolment screen and the Two-factor authentication section under Account → Security work the same way in both places:

    1. Choose Set up.
    2. Scan the QR code with an authenticator app such as 1Password, Google Authenticator or Authy. If they can't scan, Can't scan? reveals a key to type in by hand.
    3. Enter the six-digit code the app shows, and choose Turn on.

    After that, every password sign-in asks for a fresh code from the app.

    Members can't turn two-factor authentication off while your workspace requires it. The option is unavailable to them until you switch the requirement back off.

    Checking who has enrolled

    Account → Members has a 2FA column showing each member's status, so you can see at a glance who still needs to set it up. Students and members who sign in through an identity provider will show as not enrolled, which is expected, since the requirement doesn't apply to them.

    When someone loses their authenticator app

    There are no backup or recovery codes. Instead, an administrator or owner clears the person's authenticator app so they can enrol again with a new device.

    Go to Account → Members, find the person, and choose Reset two-factor authentication. They can sign in with just their password afterwards, and will be asked to set up a new authenticator app straight away.

    A reset reaches every workspace they're in

    Examplary accounts are shared across workspaces, so the authenticator app is too. Resetting it for a member who also belongs to another organization removes it there as well. Two things make sure that's never quiet: the member is emailed, told which workspace and which administrator reset it, and warned that their password is the only thing protecting the account until they enrol again — and every affected workspace gets its own user.two_factor_reset entry in its audit log.

    Before you reset, make sure the person asking is really the person who owns the account. A reset request is exactly what an attacker who already has someone's password would send you.

    If you lock yourself out

    Administrators can't reset their own two-factor authentication — that would let anyone with an admin session sidestep the requirement entirely.

    So if you lose your authenticator app, ask another administrator or owner in your workspace to reset it for you. This is the reason to have more than one administrator before you turn the requirement on.

    If nobody in the workspace can help, email Examplary support and we'll verify who you are and get you back in.

    Turning it off

    Switch Require two-factor authentication off under Account → Access & domains.

    Nobody is signed out, and nobody loses their authenticator app. Everyone who has enrolled carries on using it. The difference is that members who haven't enrolled are no longer stopped, and those who have can now turn it off for themselves under Account → Security if they want to.

    Keeping an eye on it

    Sign-in activity and changes to your security settings are recorded in the audit log, including failed sign-in attempts and every two-factor reset. See Audit logs for how to search it and what's kept.