Overview: Administrators control Multi-Factor Authentication (MFA) for the whole account in two places. An account-wide policy decides whether users are required to set it up, and a per-user reset clears someone's existing method so they can start again — useful when an employee loses the phone holding their authenticator app.
Important! Multi-Factor Authentication is available on every Buddy Punch account. It is no longer limited to accounts using Buddy Punch Payroll.
Users on accounts with Buddy Punch Payroll are always required to use MFA, whatever the account-wide policy is set to.
Instructions:
What Each Policy Option Does
The account-wide policy has three settings. The difference between them only shows up for users who haven't set up MFA yet — a user who has already enrolled is asked for a code at login under all three.
Off - Multi-factor authentication is not required. New users aren't prompted to set it up, and anyone already enrolled keeps it — and is still prompted at login — until they remove it themselves. Payroll users remain required.
Optional (Default) - Users can set up multi-factor authentication if they choose. A user who hasn't enrolled can keep logging in with just their password.
Required - Every user must set up multi-factor authentication to sign in. Anyone without it is sent to set it up the next time they log in, and can't skip past that step.
Note: Setting the policy to Off is not a way to switch MFA off for everyone. It stops new enrollment and drops the account-wide requirement, but it deliberately leaves existing users' methods in place rather than silently weakening security for someone who chose to turn it on. To clear a specific user's method, reset it as described below.
How to Set the Account-Wide MFA Policy
1. Start by clicking Settings --> Account Settings:
2. Scroll to the bottom of the page to the Multi-Factor Authentication section. The current policy is shown in the dropdown, with a description of each option beneath it:
3. Click the dropdown and choose Off, Optional, or Required, then click Save:
4. The next time someone logs in, they'll be prompted to set MFA, like so:
How to Reset a User's Multi-Factor Authentication
Resetting clears the user's existing authenticator app and passkeys. They keep their username and password, and are asked to set Multi-Factor Authentication up again the next time they log in.
Use this when an employee can't access the device holding their authenticator app if they have lost or already used their recovery codes.
1. Start by clicking Employees, then View next to the user you need to reset:
2. On their profile, click the More dropdown under their profile picture on the left, then click Reset MFA:
Note: The reset option only shows for users who currently have Multi-Factor Authentication set up. If you don't see it on someone's profile, they haven't enrolled — so there is nothing to reset, and they can simply set it up as normal.
3. Confirm the reset by clicking Reset MFA:
4. The user is automatically emailed to let them know, and will be asked to set up Multi-Factor Authentication again at their next login:
FAQs
Q: If I set the policy to Off, does that turn Multi-Factor Authentication off for everyone?
A: No. Off stops new users being prompted to enroll and drops the account-wide requirement, but anyone who already set it up keeps their method and is still asked for a code at login until they remove it themselves. Users on accounts with Buddy Punch Payroll remain required regardless. To clear an employee's method, reset it from their profile with the steps above.
Q: What happens to users who haven't set up MFA when I switch the policy to Required?
A: They're sent to set it up the next time they log in, and can't skip that step. They can still log off from that screen, but they can't reach the rest of Buddy Punch until they've enrolled.
Q: How often are users asked for a code?
A: If a user ticks Remember this browser? on the verification screen, that browser won't ask again for 14 days.
Q: Does the policy apply to the Buddy Punch mobile apps?
A: Multi-Factor Authentication applies when signing in on the website. The mobile apps don't currently prompt for it.
Q: What if our account uses Single Sign-On?
A: Where SSO is enforced, your identity provider handles sign-in, so Buddy Punch hides MFA enrollment for those users rather than asking for a second factor on top.
Q: Can users choose text message codes?
A: Only users who already had text message codes set up can keep using them. New MFA setups offer an authenticator app or a passkey instead, as both are more resistant to phishing and SIM-swap attacks than SMS.








