Enforce 2FA for all users
How to enforce two-factor authentication for all Snyk API and Web users
Learn how to enforce two-factor authentication (2FA) for all users of your Snyk API & Web account.
Two-factor authentication (2FA) strengthens authentication with an additional layer of security that requires presenting an extra piece of evidence (the possession factor) to the authentication mechanism of a website or application. To obtain the possession factor, you can use an authenticator like Google Authenticator, 1Password, Authy, or Microsoft Authenticator, which provides a random code that changes frequently.
If you are the owner of the Snyk account, you can enforce 2FA for all its users so that they have this extra layer of authentication in their profiles.
Enforce 2FA
In the Snyk app, enforce 2FA for all users as follows:
Open the Settings dropdown on the bottom-left corner of the navigation bar and click Authentication.
In the TWO-FACTOR AUTHENTICATION (2FA) SETTINGS section, click Enforce 2FA.
In the dialog that appears, enter your password and 2FA code as a security measure.
After you enforce 2FA, the following happens to the users of your account:
Users logging in without 2FA set up for their profile At login, they must follow extra steps to set up 2FA for their profile. The procedure is like steps four and five described in How to set up 2FA for your profile.
Users already logged in without 2FA set up for their profile Snyk logs out these users automatically. When they log back in, they must follow extra steps to set up 2FA for their profile. The procedure is like steps four and five described in How to set up 2FA for your profile.
Users already logged in with 2FA disabled for their profile Their 2FA becomes enabled, and Snyk asks them to enter the random code generated by the authenticator app installed on their device.
Users with 2FA enabled for their profile They do not notice a change because they already use 2FA.
Last updated
Was this helpful?

