Summary
One switch in Organization Settings → Security requires every member of your Alta organization to enter a code from an authenticator app each time they sign in.
Who this is for
Workspace Owners and Admins responsible for identity, access, and compliance — the same people who manage Single Sign-On and Domain Claiming. The control lives under Settings → Organization Settings → Security.
Before you start
Your Alta plan includes multi-factor authentication. If it doesn't, the switch is greyed out with the tooltip "Multi-factor authentication is not part of your plan" — contact Alta to enable it.
You have permission to edit authentication settings. This is the same organization permission that governs the Single Sign-On and Domain Claiming tabs, so if you can configure those, you can configure this.
Tell your team first. The requirement takes effect at the next sign-in, and anyone who isn't expecting it will hit an enrollment prompt mid-workday.
Where to find it
Open Settings.
Go to Organization Settings → Security.
The page has three tabs: Single Sign-On, Domain Claiming, and Multi-Factor Authentication. Single Sign-On is selected by default — click Multi-Factor Authentication.
Turn the requirement on
On the Multi-Factor Authentication tab you'll see a single card titled Authenticator multi-factor authentication. Its description reads "Require every organization member to enter a code from their authenticator app when signing in."
Switch on Require authenticator MFA. It is off by default.
There is no Save button — the change is written the moment you flip the switch. A "Multi-factor authentication settings updated" toast confirms it. If you see "Failed to update multi-factor authentication settings" instead, the change didn't stick; flip the switch again.
To lift the requirement, switch the same toggle back off. Same immediate save, same confirmation toast.
What your team sees
The requirement is evaluated at sign-in rather than inside the Alta app. The next time a member signs in, they're walked through enrolling an authenticator app — scanning a QR code with Google Authenticator, Microsoft Authenticator, 1Password, Authy, or similar — and then entering the six-digit code it generates. On every sign-in after that, they're asked for a fresh code.
There's nothing for members to switch on in their own user settings. The organization-level toggle is the only control.
How this fits with SSO and Domain Claiming
The three tabs on the Security page are independent controls, and Alta works out each requirement separately at sign-in:
SSO is required only when the member's email domain matches the domain aliases on an active SSO connection.
MFA is required whenever this organization switch is on.
Turning on MFA does not require SSO, and configuring SSO or claiming a domain does not turn on MFA. If you already route logins through Okta, remember that your identity provider may be enforcing its own MFA policy — decide which layer owns the second factor rather than assuming Alta's switch replaces Okta's.
Tips and common pitfalls
The switch is greyed out. Hover it — the tooltip names the blocker. "Multi-factor authentication is not part of your plan" is an entitlement issue, so contact Alta. "You do not have permission to edit authentication settings" means you need an organization owner to do it. "Multi-factor authentication settings are unavailable" means your settings didn't load — reload the page. "Saving multi-factor authentication settings" just means a save is still in flight; wait a moment.
You see "Failed to load multi-factor authentication settings" when the page opens. Alta couldn't fetch your organization settings, so the switch renders as off and disabled no matter what the real value is. Reload before concluding MFA is off.
It's one switch for the whole organization. There is no per-user, per-team, or per-account exception. If you need some people exempt, this isn't the tool for it.
Alta staff accounts are exempt. Accounts on the
altahq.comemail domain are excluded from the requirement, so an Alta team member helping inside your workspace won't be prompted. Every member on your own domains is covered.The setting is per organization. If your company runs more than one Alta organization, turn it on in each — it doesn't carry across.
Give people a heads-up before you flip it. The requirement applies at the next sign-in, including sessions that expire overnight. A short note naming a recommended authenticator app will save you a wave of "I can't get in" messages the next morning.
