Overview
Enforcing MFA ensures that all users must verify their identity with a second factor when signing in, significantly reducing the risk of unauthorized access from compromised passwords. Depending on your organization's security requirements, you can enforce any MFA method or restrict users to security keys only.
Prerequisites
Super Admin access to the Google Admin console
Instructions
Sign in to the Google Admin console
Navigate to Security > Authentication > 2-Step Verification
Select the organizational unit you want to apply this setting to
Check Allow users to turn on 2-Step Verification
Under Enforcement, select On to enforce immediately, or On from date to schedule enforcement
Under Frequency, check Allow users to trust the device
Under Methods, select the appropriate option for your organization's requirements, then click Save
Standard β Select Any to allow users to use any MFA method.
Strict (security key only) β Select Only security key to require a hardware security key or passkey, then configure these additional settings:
Set 2-Step Verification policy suspension grace period to 1 day
Under Security codes, select Allow security codes without remote access
Click Save
Note: If you haven't already, consider setting the MFA enrollment grace period to one day so new users are required to enroll shortly after their account is created.
