# Manage 2FA for Brand Accounts

[Account Administrators](https://help.impact.com/brand/what-would-you-like-to-learn-about/account-administration/account-settings/invite-and-manage-users/understanding-user-management-as-a-brand) can require all impact.com brand account members to use two-factor authentication (2FA) when they sign in from a new device. Have questions about 2FA? Check our article on [Two-Factor Authentication FAQs](https://app.gitbook.com/s/hRN1rcrim887TwHLBjac/readme/two-factor-authentication-faqs).

When invited to join an account and your sign-up method involves using a username and password, you'll be automatically signed up for 2FA and your default authentication method will be set to email.

The user experience with 2FA enabled goes as follows:

* Upon first signing in, an account member will receive a verification code on their mobile device via SMS, email, or an authentication app.
* Once an account member has successfully been authenticated, their device will automatically be saved as a trusted device—meaning they won’t need to use 2FA on subsequent sign-ins. Account members will only be asked to use 2FA again if their device has changed or unusual activity was detected.
* Account members can manage saved devices on the impact.com user profile screen.

#### Turn on 2FA for sign-in

This will enable mandatory two-factor authentication for all account members who sign in to your brand account.

1. From the top navigation bar, select ![](https://4048883401-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwMLlMoFBtKJa8ptd3zaw%2Fuploads%2Fgit-blob-1183576591b45997efe4dc81a25024640591d02a%2F245137dc972a7a7f6165b59538fcdbac8fd5bd8fee4ba9f20c1a2982c5b58b57.svg?alt=media) **\[User profile] → Settings**.
2. In the left column, under *General*, select **Account User Authentication**.
3. On the *Account user Authentication* screen ![](https://4048883401-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwMLlMoFBtKJa8ptd3zaw%2Fuploads%2Fgit-blob-d0b6669ae76a7bef06a8d6940d7ad5c16bb8d018%2F7cb018d4face8d7cceb880eb5086c812e764fbcfe6f2a0377f88bc7576973070.svg?alt=media) **\[Toggle on] User Login**.
4. Select **Save**.

   * View the users who have activated 2FA, on the **Account Users** screen, indicated by a tick in the *Two-Factor Authentication* column.

   <div data-with-frame="true"><figure><img src="https://4048883401-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwMLlMoFBtKJa8ptd3zaw%2Fuploads%2Fgit-blob-9150fe247bb2b9e4eef99a692f70b4224a4165d6%2Fb86d031317647e13314fc45ded07828b005240b4fe9bdf915bf5343fc24a5dd3.png?alt=media" alt=""><figcaption></figcaption></figure></div>

#### Turn on 2FA for PFTs

This will enable a mandatory 2FA check for account users attempting a [partner funds transfer](https://help.impact.com/brand/what-would-you-like-to-learn-about/platform-features/finance/partner-funds-transfer/transfer-funds-to-a-partner) above the transfer minimum amount — once authenticated, the PFT will go through.

1. From the top navigation bar, select ![](https://4048883401-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwMLlMoFBtKJa8ptd3zaw%2Fuploads%2Fgit-blob-1183576591b45997efe4dc81a25024640591d02a%2F245137dc972a7a7f6165b59538fcdbac8fd5bd8fee4ba9f20c1a2982c5b58b57.svg?alt=media) **\[User profile] → Settings**.
2. In the left column, under *General*, select **Account User Authentication**.
3. On the *Account User Authentication* screen, select ![](https://4048883401-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwMLlMoFBtKJa8ptd3zaw%2Fuploads%2Fgit-blob-d0b6669ae76a7bef06a8d6940d7ad5c16bb8d018%2F7cb018d4face8d7cceb880eb5086c812e764fbcfe6f2a0377f88bc7576973070.svg?alt=media) **\[Toggle on] Partner Funds Transfer**.
4. Under *Transfer minimum*, **input a value** as the minimum amount to require 2FA.
5. Select **Save**.

   <div data-with-frame="true"><figure><img src="https://4048883401-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwMLlMoFBtKJa8ptd3zaw%2Fuploads%2Fgit-blob-00bddccf23fcfb1db59647fc66de60c14637d8ab%2Ffbdcb65c97b79d5d1eb1a1eeb3eefed5af074f35c03459c0b43500cb66cf7f63.png?alt=media" alt=""><figcaption></figcaption></figure></div>

#### Manage saved 2FA devices

1. From the top navigation bar, select ![](https://4048883401-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwMLlMoFBtKJa8ptd3zaw%2Fuploads%2Fgit-blob-1183576591b45997efe4dc81a25024640591d02a%2F245137dc972a7a7f6165b59538fcdbac8fd5bd8fee4ba9f20c1a2982c5b58b57.svg?alt=media) **\[User Profile] → Edit Profile**.
2. Go to the *Security* section.
3. Under *Devices and Activity*, there is a list of saved devices for the account and the date and time of the last login from that device.
4. Select **Remove this device** if you no longer access impact.com on that device.

   <div data-with-frame="true"><figure><img src="https://4048883401-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwMLlMoFBtKJa8ptd3zaw%2Fuploads%2Fgit-blob-05b3d5298c7e14ae695ae2dfb61c72184e4e286e%2F67bc285f4ce1df707e11e9e04f32c5fddd89e3cf4704010c40f621a5e3042b10.png?alt=media" alt=""><figcaption></figcaption></figure></div>
