Two-factor authentication (2FA)

Two-factor authentication (2FA) is a way of adding additional security to your account. 2FA requires you to enter an extra code when you log in or perform some account-sensitive action (e.g. changing your password). The code is generated from an application on your computer or mobile phone.

Just want to reset your password?

Learn how to do so here.

Setting up 2FA

To enable 2FA for your account you will need an application that manages 2FA codes, such as Google Authenticator, Authy, or 1Password. Note: We don’t support 2FA over SMS.

Go to the Account Settings page and click Enable.

Account settings panel describing two-factor authentication with an Enable button.

The wizard will generate a QR code.

Dialog showing a QR code, instructions to scan with a 2FA app, input for a 6-digit code, and a manual key with copy button.

You need to scan this code with your 2FA application, then type the code your 2FA application shows. Once completed successfully, 2FA will be active on your account.

Signing in with 2FA

When you have 2FA turned on for your account, Close will ask you for a 2FA code in the following cases:

  • Logging in to Close (whether you use the web browser or the desktop app)
  • Changing your password
  • Changing your account email address
  • Disabling 2FA on your account

In each of these cases, you’ll be presented with a screen similar to the example below prompting the 6-digit code from your app.

Form prompting entry of a 6-digit authentication code to change password.

Managing/removing 2FA

If you want to disable 2FA for your account, go to the Account Settings page again and click the Disable button. Close will ask you for both your password and the 2FA code.

If you lose access to your 2FA code generator, contact support@close.com.

Admins can see which team members have enabled 2FA by going to Settings > Team Management.

Team Management page showing users, roles, contact info, and 2FA status.

Email-based 2FA

If you don’t enable 2FA on your account, Close may send a 6-digit verification code to your email address when you log in. You will then be prompted to enter that code on the login page as shown below:

Login screen asking for a 6-digit authentication code sent to your email with a Verify button.

We have this measure in place to help you maintain account security. We recommend all users enable 2FA under Settings > Account, as this will negate the need to send any verification codes to your email address.

If you have any questions about enabling or using 2FA, please contact our Support Team.

Two-factor Authentication Reset

Admins can now reset two-factor authentication for a member from Team Management when the member loses access to their authenticator app.

Resetting a member’s 2FA removes their enrolled 2FA device, logs them out of all active sessions, and sends them a password reset email. The member must reset their password, then set up 2FA again the next time they sign in if 2FA is required for the organization.

Reset 2FA for a team member

To reset a member’s 2FA:

  1. Go to Settings > Organization > Team Management.
  2. Find the member who needs help.
  3. Open the member’s actions menu.
  4. Click Reset 2FA.
  5. Review the confirmation message.
  6. Confirm the reset.

Close logs the member out of all active sessions and sends a password reset email to the member’s email address.

What the member needs to do next

After an admin resets 2FA, the member needs to:

  1. Open the password reset email from Close.
  2. Create a new password.
  3. Sign in to Close again.
  4. Set up two-factor authentication again, if required.

If the organization requires two-factor authentication for password sign-ins, the member cannot access the organization until they complete 2FA setup.

When admins can’t reset 2FA

Admins can’t reset 2FA in these cases:

  • The admin is trying to reset their own 2FA from Team Management.
  • The member belongs to multiple Close organizations.
  • The custom user account does not have permission to manage the organization.

If an admin can’t reset a member’s 2FA in Close, please contact Close Support.

Security notes

Only reset 2FA after confirming the request is legitimate. Resetting 2FA removes the member’s current 2FA device.

If the member still has access to Close, they can update their own 2FA from their account settings instead of asking an admin to reset it.