How to Set Up Two-Factor Authentication for Your Organization

Beginner 10 minutes Org Admins / All Users Team & Access Management

Enable 2FA with authenticator apps, generate recovery codes, and reset 2FA for team members as an admin.

Overview

Two-factor authentication (2FA) adds a second layer of security to your Chainsaw account. Even if your password is compromised, an attacker would also need access to your authenticator app. Chainsaw supports TOTP (Time-based One-Time Password) compatible with Google Authenticator, 1Password, Authy, and other authenticator apps.

Prerequisites

  • A Chainsaw user account
  • A TOTP-compatible authenticator app installed on your phone or device

Step 1: Navigate to Security Settings

Click your profile icon or navigate to SettingsSecurity.

Security settings page
The Security settings page shows your 2FA status

Step 2: Enable Two-Factor Authentication

Click Enable 2FA to begin setup.

Scan the QR Code

Chainsaw displays a QR code. Scan it with your authenticator app:

  1. Open your authenticator app (Google Authenticator, 1Password, Authy, etc.)
  2. Tap the “+” or “Add account” button
  3. Scan the QR code displayed on screen
2FA QR code for scanning
Scan this QR code with your authenticator app
If you can’t scan the QR code, click “Can’t scan?” to reveal the manual setup key that you can type into your authenticator app.

Enter the Verification Code

After scanning, your authenticator app displays a 6-digit code. Enter it to confirm setup:

Entering the verification code
Enter the 6-digit code from your authenticator app to confirm

Step 3: Save Your Recovery Codes

After enabling 2FA, Chainsaw generates recovery codes. These are one-time-use codes that let you log in if you lose access to your authenticator app.

Recovery codes display
Save these recovery codes in a secure location
Store recovery codes in a secure location (password manager, printed copy in a safe). Each code can only be used once. If you lose both your authenticator app and recovery codes, you’ll need an admin to reset your 2FA.

Step 4: Log In with 2FA

After enabling 2FA, your login flow changes:

  1. Enter your email and password as usual
  2. A second screen prompts for your 2FA code
  3. Open your authenticator app and enter the current 6-digit code
  4. Click Verify
2FA login prompt
After entering your password, you'll be prompted for a 2FA code

Step 5: Using a Recovery Code

If you can’t access your authenticator app:

  1. On the 2FA prompt, click Use a recovery code
  2. Enter one of your saved recovery codes
  3. Log in successfully
After using a recovery code, set up a new authenticator immediately. Each recovery code only works once.

For Administrators: Managing Team 2FA

Monitoring 2FA Adoption

Chainsaw displays a 2FA nudge banner on the dashboard for users who haven’t enabled 2FA. This encourages adoption without forcing it.

2FA nudge banner on the dashboard
Users without 2FA see a banner encouraging them to enable it

Resetting a User’s 2FA

If a team member loses access to their authenticator app and recovery codes:

  1. Navigate to AccessMembers
  2. Find the user
  3. Click Reset 2FA
  4. The user’s 2FA is cleared and they can set it up again on next login
Admin resetting a user's 2FA
Admins can reset 2FA for team members who are locked out
Only reset 2FA after verifying the person’s identity through a separate channel (in-person, phone call). Don’t reset 2FA based on email requests alone.

Supported Authenticator Apps

AppPlatformNotes
Google AuthenticatoriOS, AndroidSimple, widely used
1PasswordAll platformsIntegrated with password manager
AuthyiOS, Android, DesktopMulti-device sync, cloud backup
Microsoft AuthenticatoriOS, AndroidGood for Microsoft-heavy environments
BitwardenAll platformsOpen source password manager with TOTP

Best Practices

  • Enable 2FA on all admin and owner accounts first — These have the highest privilege level
  • Encourage all users to enable 2FA — The nudge banner helps
  • Store recovery codes separately from passwords — Don’t put them in the same place
  • Use a password manager with TOTP support — 1Password and Bitwarden can generate TOTP codes
  • Verify identity before resetting 2FA — Prevent social engineering

Next Steps