Skip to main content

How to set up multi-factor authentication

Configure MFA settings for your organisation's security.

Written by Alice Jennings

Summary

To set up multi-factor authentication (MFA) for your organisation in MirrorWeb Insight, you need to configure the MFA settings and enforcement policies. This article walks you through enabling MFA, setting enforcement rules, and configuring backup authentication methods for your users.

Prerequisites

  • Login credentials to MirrorWeb Insight

  • Admin access to your organisation's settings

  • Access to your organisation's authentication provider (if using SSO)

Step-by-Step Instructions

Step 1: Navigate to the Security Settings page

From the main navigation, click Admin and then select Security Settings from the dropdown menu.

The Admin dropdown menu with Security Settings highlighted

Step 2: Access MFA Configuration

On the Security Settings page, locate the Multi-Factor Authentication section and click Configure MFA.

The Security Settings page showing the Multi-Factor Authentication section with Configure MFA button

Step 3: Enable MFA for your organisation

  1. Toggle the Enable MFA switch to the on position

  2. Select your preferred MFA method from the dropdown:

    • Authenticator App (recommended)

    • SMS Text Message

    • Email Verification

  3. Choose the enforcement policy:

    • Required for all users

    • Required for admin users only

    • Optional (user choice)

The MFA configuration form with Enable MFA toggled on and Authenticator App selected

Step 4: Configure backup authentication methods

  1. Check Allow backup authentication methods

  2. Select which backup methods to enable:

    • Backup codes (one-time use codes)

    • Alternative email verification

    • SMS backup (if not primary method)

  3. Set the number of backup codes to generate per user (recommended: 10)

The backup authentication methods section with options selected

Step 5: Set grace period and rollout schedule

  1. Configure the Grace Period for existing users (recommended: 7 days)

  2. Choose your rollout approach:

    • Immediate enforcement for all users

    • Gradual rollout by user group

    • Manual activation per user

  3. If selecting gradual rollout, choose which user groups to enable first

The grace period and rollout schedule configuration options

Step 6: Review and save configuration

Review your MFA settings and click Save MFA Configuration to apply the changes.

The MFA configuration summary with Save MFA Configuration button highlighted

Recording: Complete MFA setup flow showing navigation through all configuration steps and successful save confirmation

Recording: Complete MFA setup flow showing navigation through all configuration steps and successful save confirmation

Notes

Important: Once MFA is enabled and enforced, users will be required to set up their MFA method on their next login. Ensure you communicate this change to your organisation before implementation.

Note: If you have SSO configured, MFA settings may be managed by your identity provider. Check with your SSO configuration to avoid conflicts between MirrorWeb Insight MFA and your identity provider's MFA requirements.

Note: Backup codes should be stored securely by users. Each backup code can only be used once and new codes must be generated when the existing set is exhausted.

Important: Admin users like Olivia Nguyen (IT Administrator) and Rebecca Thompson (Head of Compliance) will be required to complete MFA setup immediately, regardless of the grace period setting.

Did this answer your question?