> ## Documentation Index
> Fetch the complete documentation index at: https://docs.omnifact.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Security and Access

> Configure organization-wide Two-Factor Authentication requirements and manage login security policies for your workspace.

## Protect Your Workspace

The **Security and Access** tab in **User Management** gives administrators centralized control over login security for your organization. From here, you can require Two-Factor Authentication (2FA) for all team members and manage how authentication policies apply across your workspace.

<Frame>
  <img src="https://mintlify.s3.us-west-1.amazonaws.com/omnifact/images/Documentation/security-and-access.png" alt="The Security and Access tab in User Management, showing the Two-Factor Authentication enforcement toggle." />
</Frame>

<Note>
  If your organization uses SSO/SAML, authentication and 2FA requirements are handled by your identity provider. SSO users will not see Omnifact's 2FA setup options.
</Note>

### Enforcing Two-Factor Authentication

You can require 2FA organization-wide to ensure all members protect their accounts.

<Steps>
  <Step title="Open User Management">
    Go to **Team Settings** and open **User Management**.
  </Step>

  <Step title="Open Security and Access">
    Select the **Security and Access** tab.
  </Step>

  <Step title="Enable Enforcement">
    Toggle on the requirement for **Two-Factor Authentication**.
  </Step>
</Steps>

### User Experience Under Enforcement

When you enforce 2FA across your organization:

* Any user who has already configured 2FA will experience no disruption.
* Any user who has **not** yet set up 2FA will be prompted to do so the next time they attempt to log in. They must complete the 2FA setup process before they can access the Omnifact platform.

For step-by-step instructions on how users set up 2FA, see [Authentication](/en/platform/core-features/account-settings/authentication).

### Failed Login Thresholds

For security reasons, Omnifact's login throttling behavior uses a generic message and operates in the background. We do not publicly publish the exact lockout attempt thresholds or timeout durations.

Users affected by login throttling will see a generic message indicating that authentication is temporarily unavailable. For more detail on what users experience, see [Authentication](/en/platform/core-features/account-settings/authentication#failed-login-protection-throttling).
