# Two-factor authentication

ResponseHub holds a detailed picture of how your organisation handles security,
which makes it worth protecting properly. Two-factor authentication is available
to everyone, and admins can make it mandatory for the whole account.

## Require it across your account

1. Go to your account settings.

2. Select **Require two-factor authentication**.

3. Save.

Everyone on the account must then set up two-factor authentication before they
can continue using the app. Existing users are prompted the next time they sign
in.

**Worth doing before you invite your team:** Turning the requirement on early means everyone sets it up as they join, rather
than being interrupted later. See [invites](/managing-your-team/invites/).

## Setting it up as a user

ResponseHub uses standard app-based two-factor authentication, so any
authenticator app works — 1Password, Authy, Google Authenticator, Microsoft
Authenticator, and others.

1. Scan the QR code shown in ResponseHub with your authenticator app.

2. Enter the six-digit code from the app to confirm.

3. Save your backup codes somewhere safe.

Backup codes are how you get in if you lose your phone, so store them somewhere
other than the device running your authenticator app.

Once set up, you enter a code from your app when you sign in — including when
signing in to the
[Chrome extension](/chrome-extension/getting-started/).

## Single sign-on

Enterprise customers can sign in through their own identity provider instead of a
ResponseHub password. Users sign in with their work email address and are
authenticated by your provider.

Single sign-on is set up for you rather than self-serve — contact support and
they will help you configure it.

## Next steps

- [Roles](/managing-your-team/roles/)
- [Invites](/managing-your-team/invites/)