Two-Factor AuthenticationEnterprise
Two-Factor Authentication adds an extra verification step at login to protect team members' accounts. We strongly recommend enabling it to reduce the risk of password leaks and unauthorized external access.
Team-Level 2FA Setup
Go to the Security tab
Open Team Settings and navigate to the [Security] tab.
Enable Two-Factor Authentication (MFA)
Once you turn on the 'Two-Factor Authentication (MFA)' option, every team member must complete 2FA each time they access the team.
Enforce 2FA across the entire team
This setting lets you require 2FA for everyone on the team.
- By default, each user can register 2FA themselves via profile icon → personal 2FA settings. Enforcing it at the team level guarantees that every member goes through the verification process.
Setting a Password (for Social Login Users)
- You need to set a 2FA password before you can use Two-Factor Authentication.
- Accounts created via social login (such as Google or Naver) can register a password to also log in with email + password.
- You can set a password from My Page via the profile icon. If you haven't set one yet, you can also register it directly from the 2FA page.
Completing 2FA
Install an authenticator app
Install a TOTP-based authenticator app such as Google Authenticator, Microsoft Authenticator, or Authy.
Scan the QR code or enter the secret key
Scan the QR code in the app, or manually enter the provided secret key if scanning isn't possible.
Enter the 6-digit code
Enter the 6-digit code shown in your authenticator app to finish verification.
Trust this device
If you select "Trust this device for 60 days," you won't be asked to verify again on the same device for 60 days.
Save your backup codes
Keep your backup codes in a safe place.
- Store them somewhere secure in case you lose your phone or can't access your authenticator app.
- Each backup code can be used only once, and serves as an emergency way to log in without the authenticator app.
- We recommend clicking 'Download backup codes' to save them as a text file.
Tip
Enforcing 2FA at the team level requires every team member to go through verification, drastically reducing the risk of unauthorized account access or data leaks.
Auto-Delete Responses
For data like personal information that needs to be discarded after a certain period, auto-delete automatically removes responses after the period you set. Your data is safely purged to meet legal requirements — without any manual cleanup.
IP Address Verification
IP address verification restricts project access to specific IP addresses or network ranges.