MFA and account protection

Enabling multi-factor authentication for your account or enforcing it org-wide, plus recovery codes and what to do if you lose your device.

Updated 27 Jul 2026

Multi-factor authentication (MFA) makes account takeover dramatically harder. Even if a password is leaked, a second factor stops the attacker. Clment supports authenticator apps (Google Authenticator, Authy, 1Password, etc.) and backup codes.

Enabling MFA on your account

  1. Settings → Security → Sign-in methods, find the Two-factor authentication row, and click Manage.
  2. Choose Enabled.
  3. Scan the QR code with your authenticator app, or copy the secret manually.
  4. Enter the 6-digit code your app generates.
  5. Save the backup codes that appear next — these are your fallback if you lose the device.

That’s it. Next time you sign in (after your current session expires), Clment asks for a verification code in addition to your password.

Backup codes — read this first

Backup codes are one-time-use 8-digit codes that work in place of a verification code. You get 10 of them when you enable MFA. Store them somewhere your authenticator app can’t reach:

  • Password manager (1Password, Bitwarden, etc.) — a dedicated “MFA backup” note.
  • Printed copy in a safe — old-school but bulletproof.
  • NOT in your phone’s photos, screenshots folder, or on your laptop’s desktop.

Once you use a backup code, it’s invalidated. You can generate a fresh set any time — Settings → Security → Sign-in methods → Two-factor authentication → Manage, then Regenerate backup codes — but the old ones stop working. Clment nudges you with a banner on the Security page once you’re down to three codes or fewer.

What if I lose my phone?

In order of preference:

  1. Use a backup code to sign in, then set up a new authenticator from Settings → Security. About 5 minutes total.
  2. Reset two-factor yourself if you have no backup codes. On the verification-code screen choose Lost your authenticator?Reset my two-factor. For your security the reset takes effect after a 24-hour delay, and we email you a cancel link in case it wasn’t you. After the window, sign in with your password and set up a new authenticator (you’ll get a fresh set of backup codes).
  3. Contact support if you need access sooner than 24 hours — we verify your identity and reset two-factor for you.

This is why backup codes matter — with them you’re back in immediately; without them the fastest self-service path is the 24-hour reset. Save the codes properly when you first enrol. For the full walkthrough, see Can’t sign in?.

Enforcing MFA org-wide

Admins can require MFA for every user in the org. Two routes to the same setting, both on Settings → Security:

  • In the Manage dialog on the Two-factor authentication row, pick Required for organization.
  • Or use the Require 2FA for organization button — the one admins who sign in with SSO only will see, since they have no personal password row.

The card shows a 2FA required / 2FA not required badge so you can tell the current policy at a glance.

Effects:

  • Existing users without MFA are walked through enrollment on their next sign-in. They can’t access any data until enrollment completes.
  • New users must enroll MFA during their first sign-in.
  • SSO-only users are exempt — their identity provider’s MFA policy applies. Forcing a second factor on top of an IdP’s existing MFA is redundant.

The exemption is important: if you require SSO via Microsoft Entra (and Entra requires MFA), don’t also turn on Clment’s own requirement — your users would get prompted twice.

Recovery code use cases

Beyond device loss, backup codes are useful for:

  • Travel — if you’re going somewhere without your usual phone (a remote site, hiking, etc.) and want to access Clment on a borrowed laptop, take a printed backup code.
  • Phone-on-fire scenario — your phone crashed mid-day and you need to sign in immediately.
  • Setup transition — moving from one authenticator app to another, a backup code bridges the gap.

Disabling MFA on your own account

Settings → Security → Sign-in methods → Two-factor authentication → Manage, then choose Disabled and confirm.

You’ll be asked to enter your password and either a verification code or a backup code to confirm.

If the org policy is set to Required for organization, you can’t disable MFA — you can only re-enroll with a different device.

What MFA protects against (and doesn’t)

Protects against:

  • Stolen / leaked passwords.
  • Credential-stuffing attacks (re-used password from another breach).
  • Phishing that doesn’t account for a second factor (most kit-based attacks).

Doesn’t protect against:

  • AiTM phishing that proxies your live session and steals the cookie after MFA.
  • Device theft with active session — if someone has your unlocked laptop and you’re already signed in, MFA isn’t between them and your data. Lock your laptop.
  • Insider threats — MFA doesn’t help if the threat is someone who already has legitimate access.

See also

Still have questions?

Instant article search