Summary
To set up multi-factor authentication (MFA) for your organisation in MirrorWeb Insight, you need to configure the MFA settings and enforcement policies. This article walks you through enabling MFA, setting enforcement rules, and configuring backup authentication methods for your users.
Prerequisites
Login credentials to MirrorWeb Insight
Admin access to your organisation's settings
Access to your organisation's authentication provider (if using SSO)
Step-by-Step Instructions
Step 1: Navigate to the Security Settings page
From the main navigation, click Admin and then select Security Settings from the dropdown menu.
Step 2: Access MFA Configuration
On the Security Settings page, locate the Multi-Factor Authentication section and click Configure MFA.
Step 3: Enable MFA for your organisation
Toggle the Enable MFA switch to the on position
Select your preferred MFA method from the dropdown:
Authenticator App (recommended)
SMS Text Message
Email Verification
Choose the enforcement policy:
Required for all users
Required for admin users only
Optional (user choice)
Step 4: Configure backup authentication methods
Check Allow backup authentication methods
Select which backup methods to enable:
Backup codes (one-time use codes)
Alternative email verification
SMS backup (if not primary method)
Set the number of backup codes to generate per user (recommended: 10)
Step 5: Set grace period and rollout schedule
Configure the Grace Period for existing users (recommended: 7 days)
Choose your rollout approach:
Immediate enforcement for all users
Gradual rollout by user group
Manual activation per user
If selecting gradual rollout, choose which user groups to enable first
Step 6: Review and save configuration
Review your MFA settings and click Save MFA Configuration to apply the changes.
Recording: Complete MFA setup flow showing navigation through all configuration steps and successful save confirmation
Notes
Important: Once MFA is enabled and enforced, users will be required to set up their MFA method on their next login. Ensure you communicate this change to your organisation before implementation.
Note: If you have SSO configured, MFA settings may be managed by your identity provider. Check with your SSO configuration to avoid conflicts between MirrorWeb Insight MFA and your identity provider's MFA requirements.
Note: Backup codes should be stored securely by users. Each backup code can only be used once and new codes must be generated when the existing set is exhausted.
Important: Admin users like Olivia Nguyen (IT Administrator) and Rebecca Thompson (Head of Compliance) will be required to complete MFA setup immediately, regardless of the grace period setting.






