Configure two-factor authentication
You can set the two-factor authentication flow right after installation or any time later. When you enable two-factor authentication after installation, make sure to set the flow before you configure user roles.
Enable and set two-factor authentification
To set the two-factor authentication flow, follow the steps below:
Click Authentication > Required Actions.
For the Configure OTP option, select the Default Action checkbox and make sure the Enabled checkbox is selected.

After that, the action appears in the Required User Actions field on the Details tab for each new user you create.

To configure the OTP policy, navigate to the OTP Policy tab. The recommended setup is shown below.
infoIf you change any of the default settings shown above, the Google Authenticator application becomes unavailable for the two-factor authentication flow.
To disable two-factor authentication for the password reset flow, go to Authentication > Flows.

In the drop-down field on the left, select the Reset Credentials flow.
In the Reset - Conditional OTP section, select DISABLED.
(Optional) To enable the two-factor authentication for an existing user (if any), navigate to Users and click the user's ID or Edit. Then, navigate to the Details tab and, in the Required User Actions field, select the Configure OTP option.
noteStep 7 is not needed when you configure the two-factor authentication flow before you create any users in the WorkFusion User Management or import them to it.
Once you have set the flow, at their first login, all users get redirected to the two-factor authenticator screen:

After users complete the two-factor authentication flow, they receive a confirmation email to the address associated with their account in Work.AI. The Configure OTP action is no longer shown in the Required User Actions field on the Details tab for the particular user.

Also, if you switch to the Credentials tab for the particular user, the Manage credentials section will include an otp record:

Erase existing OTP credentials
In case a user loses their device, proceed this way:
Go to Users and click the user's ID or the Edit to get to the user settings.
On the Credentials tab, delete the current otp record.

Switch to the Details tab. In the Required Actions field, add the Configure OTP action.
As a result, when the user attempts to log in to Work.AI next time, they will have to go through the OTP setup procedure again.