Illizeo offers two-factor authentication through a TOTP app, enabled per role, plus a configurable password policy. Here is exactly what each one covers.
Available MFA methods #
| Method | Available in Illizeo |
|---|---|
| TOTP app (Google Authenticator, Authy, 1Password…) | Yes — the only supported method |
| WebAuthn / passkey | No |
| One-time SMS | No |
| Emailed code | No |
| Hardware security key (YubiKey…) | No |
Step-by-step #
-
Check that your plan includes two-factor authentication #
2FA is a plan feature. If it does not appear on your role screens, it is not part of your subscription.
-
Turn it on per role #
2FA is attached to a role, not to individual employees: Roles → Security. Everyone holding that role will have to enrol at their next sign-in.
-
Let employees enrol #
At the next sign-in a QR code appears: the employee scans it with their authenticator app, then types the six-digit code to confirm.
-
Set the password policy #
Settings → Authentication → Password. You set the minimum length, whether uppercase, lowercase, digits and symbols are required, and how many previous passwords may not be reused.
-
Decide on expiry #
A single toggle forces a password change every 90 days. It is a switch, not a free duration: either 90-day expiry applies or it does not. An expired password sends the user to a change screen on their very next request.
-
Set the session duration #
One session duration applies to the whole workspace, across all devices.
FAQ #
Can 2FA be required for one specific person?
No. The unit is the role. To target someone, go through a role that contains them.
What if an employee loses their phone?
An administrator resets their two-factor authentication from their record; the employee re-enrols at the next sign-in. There are no recovery codes to keep.
Are passwords checked against breach databases?
No. Illizeo does not query any external compromised-password service.
What if SSO is on?
Strong authentication is then your identity provider’s. Illizeo’s 2FA covers local password sign-in.
Can expiry be set to something other than 90 days?
No. The duration is fixed; only whether it applies is configurable.
What does not exist #
No WebAuthn or passkeys, no SMS, no emailed code, no hardware security key. No single-use recovery codes. No check against a compromised-password database. No separate web and mobile idle timeouts, and no scheduled forced logout.
See IP allowlist and restrictions #
Learn to restrict access by IP or geography.
