Two-factor authentication asks for a six-digit code from an authenticator app on top of a password, so a leaked or guessed password isn't enough on its own to get into an account.
Anyone can switch it on for themselves under Account → Security. As an administrator, you can go further and require it for everyone in your workspace.
Requiring two-factor authentication across a workspace is available on the Examplary for organizations plan. Individual members can turn it on for their own account on any plan. If you're interested in upgrading, contact us via hi@examplary.ai.
Who it applies to
Two-factor authentication protects password sign-ins. That's the only place it makes sense, so several groups are deliberately left out:
| Who | Affected? | Why |
|---|---|---|
| Teachers and admins with a password | Yes | This is what the second factor protects |
| Students using a magic code or link | No | There's no password to protect |
| Anyone signing in through Google, Entree Federatie or your own identity provider | No | Your identity provider owns the policy — set it up there |
| API keys and OAuth access tokens | No | Separate credentials, issued deliberately, revoked separately |
Requiring two-factor authentication does nothing for a workspace that already signs in through an identity provider — those members never enter an Examplary password. Configure the requirement in Google Workspace, Entree, Entra ID or wherever your accounts live. See Setting up single sign-on.
Turning it on for your workspace
Go to Account → Access & domains and switch on Require two-factor authentication.
From then on, any member who signs in with a password and hasn't set up an authenticator app is stopped at a Set up two-factor authentication screen and can't use Examplary until they've enrolled. They don't need an invitation or a link, the screen appears on its own the next time they load the dashboard.
Set up your own authenticator app under Account → Security before you switch the requirement on, and tell your colleagues it's coming. Nobody is locked out of their account by this — they just can't get past the enrolment screen — but people tend to hit it mid-task, and it's a better experience when they're expecting it.
Switching the setting on can take up to 15 minutes to reach everyone in the workspace. Members who are already signed in when you switch it on might be able to carry on using Examplary until they sign out, at which point they'll be stopped at the enrolment screen.
What your members will see
The enrolment screen and the Two-factor authentication section under Account → Security work the same way in both places:
- Choose Set up.
- Scan the QR code with an authenticator app such as 1Password, Google Authenticator or Authy. If they can't scan, Can't scan? reveals a key to type in by hand.
- Enter the six-digit code the app shows, and choose Turn on.
After that, every password sign-in asks for a fresh code from the app.
Members can't turn two-factor authentication off while your workspace requires it. The option is unavailable to them until you switch the requirement back off.
Checking who has enrolled
Account → Members has a 2FA column showing each member's status, so you can see at a glance who still needs to set it up. Students and members who sign in through an identity provider will show as not enrolled, which is expected, since the requirement doesn't apply to them.
When someone loses their authenticator app
There are no backup or recovery codes. Instead, an administrator or owner clears the person's authenticator app so they can enrol again with a new device.
Go to Account → Members, find the person, and choose Reset two-factor authentication. They can sign in with just their password afterwards, and will be asked to set up a new authenticator app straight away.
Examplary accounts are shared across workspaces, so the authenticator app is
too. Resetting it for a member who also belongs to another organization
removes it there as well. Two things make sure that's never quiet: the member
is emailed, told which workspace and which administrator reset it, and warned
that their password is the only thing protecting the account until they enrol
again — and every affected workspace gets its own user.two_factor_reset
entry in its audit log.
Before you reset, make sure the person asking is really the person who owns the account. A reset request is exactly what an attacker who already has someone's password would send you.
If you lock yourself out
Administrators can't reset their own two-factor authentication — that would let anyone with an admin session sidestep the requirement entirely.
So if you lose your authenticator app, ask another administrator or owner in your workspace to reset it for you. This is the reason to have more than one administrator before you turn the requirement on.
If nobody in the workspace can help, email Examplary support and we'll verify who you are and get you back in.
Turning it off
Switch Require two-factor authentication off under Account → Access & domains.
Nobody is signed out, and nobody loses their authenticator app. Everyone who has enrolled carries on using it. The difference is that members who haven't enrolled are no longer stopped, and those who have can now turn it off for themselves under Account → Security if they want to.
Keeping an eye on it
Sign-in activity and changes to your security settings are recorded in the audit log, including failed sign-in attempts and every two-factor reset. See Audit logs for how to search it and what's kept.