If 2FA is optional, only the security-conscious enable it. To get the protection at population scale, you have to enforce. ActiveManage lets you enforce gradually with sensible grace periods so you don't lock out half the user base on rollout day.
Enforcement Levels
- Off: Users can enable 2FA but aren't reminded.
- Encouraged: Banner prompts users to enable; they can dismiss.
- Required after grace: Banner with countdown; after the grace period the user must enrol before reaching any protected page.
- Required immediately: No grace; next sign-in must enrol.
Setting It Up
- Open Site Settings → Security → Two-Factor Authentication.
- Pick the enforcement level — “Required after grace” is the recommended rollout pattern.
- Set the grace period (typically 7–14 days).
- Decide whether to apply enforcement globally or by security group (so admins are forced first, customers later).
- Save. The platform schedules enforcement and starts showing banners.
Worked Rollout
- Week 1: Enforce for the Admin group only. They've already mostly enrolled — issues surface immediately and are easy to fix.
- Week 2: Add Staff group. Help-desk volume rises briefly as users hit the banner.
- Week 4: Add External-customer group with 14-day grace. Email campaign two weeks before to warn users.
- Week 6: Audit — anyone still without 2FA gets a tighter grace or is manually blocked until enrolled.
Note: Always have a break-glass admin account exempt from enforcement. Document it and store its credentials in your team's password manager.