Skip to main content

Options to Enforce Two-Factor Authentication (2FA)

Updated over 2 weeks ago

Using 2FA protects from unauthorised access to a person's account and increases data security.

Due to Xero requirements, ApprovalMax enforces 2FA for all users who access Xero-connected Organisations.

ApprovalMax is now offering two types of 2FA enforcement:

  1. ​Soft enforcement: every time users reload a webpage, they will be prompted to set up 2FA. An email notification with a reminder will be sent additionally on a weekly basis:

  2. Hard enforcement: every user action will redirect the user to the 2FA enforcement webpage. An email notification with a reminder will be sent on a daily basis:


    How to set up:
    Administrators can choose between the two enforcement types on the Organisation page:



2FA enforcement is turned on for all Xero-connected Organisations.


For Organisations that are not connected to Xero, the enforcement of 2FA is optional.






Did this answer your question?