Skip to main content
Screenshot2026 02 16at5 05 15pm

Overview

Two-factor authentication (2FA) adds an extra layer of security to your Dovetail account. When enabled, you’ll verify your identity using an authenticator app each time you sign in, protecting your account even if your password is compromised.

What to know before you get started

Before your start configuring two-factor authentication, review the below requirements and dependencies.

Who can use two-factor authentication?

2FA is available for users who sign in with a password. Important limitations:
  • SSO users: If you sign in using SSO, Google, or Microsoft, 2FA is not available in Dovetail. Your identity provider may enforce MFA through their own security policies.
  • Free plan users: By default, free plan users don’t have access to Authentication settings, so password, Google, and Microsoft login methods are automatically enabled.

Requirements

Before you can enable MFA, you’ll need:
  1. Password authentication enabled in your workspace’s Authentication settings
  2. To be logged in using a password-based account (not SSO, Google, or Microsoft)
  3. An authenticator app installed on your mobile device, such as:
    • Google Authenticator
    • Authy
    • Microsoft Authenticator
    • 1Password
    • Or any other TOTP-compatible authenticator app
If requirements one and two are met, users will see the following option within Authentication settings:
Image(13)

How to set-up 2FA

  1. Click your profile menu and select Settings
  2. In the left sidebar, navigate to Your Profile > Account
  3. Scroll to the Multi-factor authentication section
  4. Click Enable
  5. On the “Secure Your Account” screen, scan the QR code using your authenticator app
  6. Enter the 6-digit verification code generated by your authenticator app
  7. Click Continue to complete the setup
Once enabled, you’ll be asked to enter a code from your authenticator app every time you sign in.
If you have trouble scanning the QR code, most authenticator apps also offer a “Trouble Scanning?” option that allows you to manually enter a setup key.

Signing in with 2FA

After 2FA is enabled, your sign-in process will include an additional step:
  1. Enter your email and password as usual
  2. You’ll see a “Verify Your Identity” screen
  3. Open your authenticator app and locate the 6-digit code for your Dovetail account
  4. Enter the code in the provided field
  5. (Optional) Check “Remember this device for 30 days” to skip MFA verification on this device for 30 days
  6. Click Continue
The verification codes refresh every 30 seconds, so make sure to enter the current code before it expires.
Best Practices
  • Use a trusted device: Only enable “Remember this device for 30 days” on devices you own and trust
  • Keep your authenticator app secure: Protect the device running your authenticator app with a passcode or biometric lock
  • Don’t share codes: Never share your one-time codes with anyone, including support staff

Managing your 2FA settings

Disabling 2FA

If you want to turn off 2FA:
  1. Go to Settings > Your profile > Account
  2. In the Multi-factor authentication section, you’ll see your authenticator app status showing “Verified”
  3. Click Reset
  4. Confirm by clicking Reset and log out
Note: Resetting 2FA will automatically log you out so the changes take effect. When you log back in, you’ll be able to choose a new authentication method or re-enable 2FA.
Clean Shot2026 02 05at13 42 55@2x

Lost access to your authenticator app?

If you lose access to your device or authenticator app and can’t sign in:
  1. Contact our support team for assistance
  2. Support will verify your identity and reset 2FA for your account
  3. Once reset, you’ll be able to sign in with just your password and can set up 2FA again if desired
Important: For security reasons, only you can disable 2FA while signed in. If you’re locked out, support assistance is required.

Frequently Asked Questions

Currently, Dovetail only supports authenticator apps for 2FA. SMS and email options are not available.
Before switching devices, disable 2FA in your settings, then re-enable it on your new device. If you’ve already switched and can’t access your codes, contact support for a reset.
Currently, 2FA is optional and managed individually by each user. Workspace-wide enforcement is not available at this time.
Yes, unless you check “Remember this device for 30 days” during sign-in. This option skips 2FA verification on that specific device for 30 days.
Users can use any authentication app (ex: Okta verify, 1password, Google authenticator)