HomeAuthentication & SSOTwo-factor authentication

Two-factor authentication

Add a second factor at sign-in using a TOTP authenticator app, for all users or a selected group.

Two-factor authentication (2FA) adds a second check at sign-in, so a password or identity-provider login alone is not enough to access the intranet. It works regardless of how a user signs in — it applies to both local directory accounts and users who sign in through SAML single sign-on.

Before you start

  • You need a Power User account to enable and target two-factor authentication.
  • Each user needs an authenticator app on their phone (for example Google Authenticator or Microsoft Authenticator).

Two-factor authentication is configured in Control Panel > 2-Factor Authentication.

How it works

Interact uses time-based one-time passwords (TOTP), the open standard supported by common authenticator apps. When 2FA is required, the user pairs their authenticator app with Interact once. From then on, at each sign-in they enter the current six-digit code from the app in addition to their normal credentials. The code changes every 30 seconds and is generated on the device, so it cannot be reused or intercepted like a static password.

Who it applies to

You control who must use two-factor authentication. It can be enforced for everyone, or for a selected group of users — for example, only the IT team or another group with elevated access. This lets you apply stronger sign-in requirements where they matter most without imposing them on every user.

Tip: Start by requiring 2FA for administrators and users with access to sensitive areas, then widen the requirement as your rollout plan allows.

What the user experiences

The first time a user signs in after 2FA is required for them, Interact prompts them to set it up: they scan a QR code (or enter a key) into their authenticator app to pair it, then confirm with the first generated code. On every subsequent sign-in, they enter their credentials and the current six-digit code.

Section: Authentication & SSO