Require two-factor for your workspace
Admins can force every member to enroll in two-factor authentication. Anyone without it is sent to the setup screen on their next sign-in and cannot reach the app until they finish.
One switch makes two-factor compulsory for everyone in the workspace: Settings > Policies & audit > Require 2FA for every member. Members without it are held on a setup screen at their next sign-in and cannot reach documents, templates or settings until they enroll.
Who can do this
The admin role, on Growth and above. Managers and members don't see the Policies page at all.
Turn on two-factor enforcement
-
Open Settings > Policies & audit.
-
In the Work policies card, switch on Require 2FA for every member.

There's no save button here. Policy changes write the moment you flip them. The card says as much in a line under its heading.
Set up your own authenticator before you turn the policy on. You're covered by the rule too, and it's a poor moment to discover your phone is at home.
What members see at their next sign-in
Anyone without two-factor is redirected to a page headed Set up two-factor the next time their account loads, whichever address they were trying to open. From there they scan a QR code, verify one 6-digit code and save ten backup codes, exactly as described in setting up two-factor authentication. Once they click Done they land on the dashboard and the app behaves normally again.
Members who already have two-factor on notice nothing at all. Their sign-in was already asking for a code.
Give people a heads-up before you flip the switch. Somebody on the road with no authenticator installed will be stuck at that screen until they set one up, and there's no way to skip past it.
Turn 2FA enforcement back off
Turn the same switch off and enforcement stops immediately. Nobody is un-enrolled. Everyone who set up an authenticator carries on using it until they disable it themselves.
If something goes wrong
- The switch won't move, and an Upgrade chip sits beside the Work policies heading. Your plan doesn't include workspace enforcement. Clicking the switch opens a panel explaining the feature rather than moving you off the page.
- You cannot find Policies & audit in Settings. Only admins see it. Ask whoever holds the admin role in your workspace.
- A member says they are stuck on the setup screen. They have not finished enrolling. Walk them through the QR step, or have them use the manual secret if their camera is refusing to cooperate.
- Someone lost their phone after enrolling. Their ten backup codes get them in. If those are gone too, our support team is the only route to a reset.
- A new joiner never saw the screen. They enrolled during their first sign-in without noticing what prompted it. That's the expected behavior.
Frequently asked questions
What happens to members who are already signed in?
Nothing right away. The rule is applied when the app next loads their account, which for an open tab means their next page load or their next sign-in. From that point they are held on the setup screen until they finish enrolling.
Can a member turn their own two-factor off afterwards?
They can open the disable dialog and complete it, but it buys them nothing. The requirement flips straight back on and their next sign-in lands on the setup screen again. In practice the only reason to do it is moving the authenticator to a new phone.
Does this cover people who sign my documents?
No. Enforcement applies to members of your workspace signing in to the app. External recipients open a signing link and never have an account, so nothing changes for them. Add an access PIN or signer verification to an envelope if you want a check on that side.
What about someone who signs in with Google?
They are covered like everyone else. Provider sign-in and two-factor stack, so after Google hands them back to us they still have to enroll and then supply a code each time. No password is needed at any point in that flow.
Will I lock myself out by turning this on?
No. Admins get no exemption here, so the setup screen catches you as well if you have not enrolled. Enrolling takes a couple of minutes with an authenticator app on your phone. Your admin role survives it untouched, and you can still open **Policies & audit** to switch the rule back off.
How do I see who has enrolled?
There's no per-member two-factor column on the **Team** page today. Enforcement answers the question for you. Once the policy is on, anybody who has not enrolled cannot use the workspace at all, so your roster of active users is also your roster of enrolled users.
Keep going
Set up two-factor authentication
Scan a QR code in an authenticator app, verify one 6-digit code, and save the ten backup codes. Sign-in then asks for a code after your password.
ReadDocument policies: signing window, reminders and forwardingGrowth and up
Set the signing window, reminder cadence and forwarding rule once, and every document you send afterwards starts from those values.
ReadWorkspace roles - Admin, Manager, Member and billing
What each of the three workspace roles can do, who is allowed to change a role, and why the last admin cannot be demoted or removed.
ReadChange your password
Update your password from Settings, Security. You stay signed in here, every other session is dropped, and the rule is eight characters with a letter and a digit.
Read